CVE-2019-19022: ITERM2
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.
Affected products
- ITERM2 ITERM2: up to and including 3.3.6
Published 2019-11-17. Last modified 2026-06-17.