Executive brief
Kitty is a popular cross-platform terminal emulator that uses the computer's graphics processor for performance. A security flaw in how it handles images allows a malicious process or script to crash the terminal or potentially take control of the user's computer. This could lead to data loss from open terminal sessions or unauthorized access to the system if a user views a malicious file or visits a website that sends specific commands to the terminal.
Technical details
A heap-based buffer overflow exists in the `load_image_data()` function within `kitty/graphics.c`. The vulnerability is triggered when processing an APC graphics protocol command using the PNG format (f=100). While the code attempts to resize the buffer by doubling its capacity when the payload exceeds the current size, it fails to verify if the new doubled capacity is sufficient before performing a `memcpy`. An attacker can exploit this by providing a payload that is more than twice the initial buffer size, leading to an out-of-bounds write. This can be triggered by any process capable of writing to the terminal's stdin. The issue is fixed in version 0.47.0 (and backported in some contexts to 0.46.3).
Affected products
- kovidgoyal Kitty <= 0.46.2
Timeline
- 2026-03-21: other: Version 0.46.2 released
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched: Fixed in version 0.47.0