Apple Patches macOS Terminal Flaw Used to Sneak Data Out via DNS Requests
A researcher has detailed how a quirk in the macOS Terminal app could be exploited to secretly send data off a device using DNS requests, a technique known as DNS exfiltration. The underlying behaviour, originally discovered by another researcher, allowed a specific sequence of ANSI escape codes (special text formatting characters) to trigger DNS lookups without the user's knowledge.
The real danger emerged when combined with AI tools. Researchers found that large language models (LLMs) and AI agents running in command line environments can be manipulated into producing these escape codes as part of their output. This meant an attacker could potentially hijack an AI-powered command line tool and use it to quietly leak sensitive data from a victim's machine, all without obvious signs of compromise.
Apple has since fixed the Terminal behaviour that enabled this specific exfiltration method, and the researcher was credited in Apple's release notes. However, the broader issue remains: many command line tools that integrate LLMs do not properly filter or encode control characters before displaying them, which could still lead to unexpected or unsafe terminal behaviour depending on the software in use.