THREAT OPS › Threat News › From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
<p>This is a follow-up to my previous <a href="https://embracethered.com/blog/posts/2024/terminal-dillmas-prompt-injection-ansi-sequences/">Terminal DiLLMa research</a>, and there is a positive outcome: Apple fixed a macOS Terminal behavior that enabled a DNS-based data exfiltration technique.</p> <p><a href="https://embracethered.com/blog/images/2026/ansi-esc/dillma-fixed.png"><img alt="dillma fi
Indicators of compromise
- https://dgl.cx/2023/09/ansi-terminal-security#apple-terminal-dns-leaksurl