Apple disclosed that macOS Tahoe 26.1 fixed a Terminal issue that allowed ANSI escape sequences in rendered output to trigger DNS requests, creating a path for data exfiltration when attacker-controlled content was displayed in the terminal. The flaw was reported in December 2024 and was later documented in Apple's broader macOS security bulletin, which lists numerous fixes across privacy protections, sandboxing, privilege boundaries, memory safety, Gatekeeper restrictions, and denial-of-service conditions.
A public write-up showed how the behavior could be abused through an LLM-enabled CLI workflow: malicious spreadsheet content influenced the model's output, which included escape codes that macOS Terminal interpreted as DNS lookups carrying stolen data. The researcher said the issue demonstrates that terminal-rendered model output must be treated as untrusted input, while Apple's bulletin indicates the fix shipped in Tahoe 26.1 alongside many other vulnerability patches affecting both Apple components and some bundled third-party open-source software.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Apple made a further update to the macOS Tahoe 26.1 security bulletin, continuing to revise the published details of fixed vulnerabilities.
Apple later updated its macOS Tahoe 26.1 security bulletin to revise the documented security content for the release.
Apple released macOS Tahoe 26.1, addressing numerous vulnerabilities across the OS. The release included the fix for the macOS Terminal behavior that allowed ANSI escape sequences to trigger DNS lookups.
A researcher reported to Apple that macOS Terminal could interpret ANSI escape sequences in attacker-controlled output and trigger DNS requests, enabling DNS-based data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.