In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Iterm2
Iterm2 iterm2 |
|
CPEs | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* | |
Vendors & Products |
Iterm2
Iterm2 iterm2 |

Status: PUBLISHED
Assigner: mitre
Published: 2024-06-16T00:00:00
Updated: 2024-08-02T04:12:24.681Z
Reserved: 2024-06-16T00:00:00
Link: CVE-2024-38395

Updated: 2024-08-02T04:12:24.681Z

Status : Analyzed
Published: 2024-06-16T01:15:48.537
Modified: 2025-06-18T16:40:48.790
Link: CVE-2024-38395

No data.