← Back to feed
AI SecurityEmerging1 sourceJul 16, 2026 · 09:13via Embrace The Red (AI agent security)

From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal

Brief

This is a follow-up to my previous Terminal DiLLMa research , and there is a positive outcome: Apple fixed a macOS Terminal behavior that enabled a DNS-based data exfiltration technique.

DNS Requests via ANSI Escape Codes

David Leadbeater originally discovered an interesting behavior in the macOS Terminal app that allowed a special sequence of ANSI escape codes to issue DNS requests.

In short, this triggered a DNS request from the macOS Terminal app:

Read more on Embrace The Red (AI agent security)