📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Government/Federal Agencies HIGH 47m Global malware Enterprise/Multiple Sectors CRITICAL 49m Global data_breach E-commerce and Retail CRITICAL 56m Global vulnerability Government and Public Administration CRITICAL 1h Global vulnerability Technology/Software Development CRITICAL 1h Global general Industrial Control Systems/Manufacturing HIGH 2h Global data_breach Social Media and Virtual Reality Platforms HIGH 2h Global vulnerability Enterprise Security / All Sectors HIGH 2h Global apt Government and Defense CRITICAL 2h Global general Technology / Consumer Protection MEDIUM 2h Global vulnerability Government/Federal Agencies HIGH 47m Global malware Enterprise/Multiple Sectors CRITICAL 49m Global data_breach E-commerce and Retail CRITICAL 56m Global vulnerability Government and Public Administration CRITICAL 1h Global vulnerability Technology/Software Development CRITICAL 1h Global general Industrial Control Systems/Manufacturing HIGH 2h Global data_breach Social Media and Virtual Reality Platforms HIGH 2h Global vulnerability Enterprise Security / All Sectors HIGH 2h Global apt Government and Defense CRITICAL 2h Global general Technology / Consumer Protection MEDIUM 2h Global vulnerability Government/Federal Agencies HIGH 47m Global malware Enterprise/Multiple Sectors CRITICAL 49m Global data_breach E-commerce and Retail CRITICAL 56m Global vulnerability Government and Public Administration CRITICAL 1h Global vulnerability Technology/Software Development CRITICAL 1h Global general Industrial Control Systems/Manufacturing HIGH 2h Global data_breach Social Media and Virtual Reality Platforms HIGH 2h Global vulnerability Enterprise Security / All Sectors HIGH 2h Global apt Government and Defense CRITICAL 2h Global general Technology / Consumer Protection MEDIUM 2h
Vulnerabilities

CVE-2026-33633

High ⚡ Exploit Available
CWE-122 — Weakness Type
Published: May 19, 2026  ·  Modified: May 26, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.

🤖 AI Executive Summary

CVE-2026-33633 is a heap buffer overflow vulnerability in Kitty terminal versions 0.46.2 and below, triggered via APC graphics protocol commands with PNG format declarations. An attacker with stdin access can crash the terminal immediately, with potential for remote code execution through controlled overflow of both length and content. This vulnerability poses significant risk to organizations using Kitty for remote terminal access or automated terminal processing.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 23, 2026 03:40
🇸🇦 Saudi Arabia Impact Assessment
Saudi government agencies (NCA, NCSC) and financial institutions (SAMA-regulated banks) using Kitty for secure terminal access face immediate DoS risk. Telecommunications sector (STC, Mobily) and energy sector (Saudi Aramco) utilizing Kitty in automated monitoring or remote administration systems are vulnerable to service disruption and potential lateral movement. Healthcare organizations (MOH) and critical infrastructure operators relying on Kitty for administrative access could experience operational disruption. The vulnerability is particularly concerning for organizations using Kitty in containerized or cloud environments where multiple processes may share terminal access.
🏢 Affected Saudi Sectors
Government and Public Administration Banking and Financial Services Telecommunications Energy and Utilities Healthcare Critical Infrastructure Information Technology Services
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running Kitty versions 0.46.2 and below using asset inventory and endpoint detection tools
2. Restrict stdin access to Kitty terminals to trusted processes only; implement principle of least privilege
3. Disable APC graphics protocol support if not required (configure Kitty with graphics disabled)
4. Monitor for unexpected terminal crashes and correlate with APC protocol commands in logs

PATCHING GUIDANCE:
1. Upgrade to Kitty version 0.47.0 or later immediately when available
2. For systems unable to patch immediately, implement network segmentation to limit untrusted input sources
3. Deploy application whitelisting to prevent unauthorized processes from writing to terminal stdin

COMPENSATING CONTROLS:
1. Implement input validation and sanitization for any process writing to Kitty stdin
2. Use terminal multiplexers (tmux, screen) with restricted access controls as intermediary layer
3. Enable core dumps and crash logging to detect exploitation attempts
4. Deploy host-based IDS rules to detect APC protocol commands with PNG format declarations (f=100)

DETECTION RULES:
1. Monitor for Kitty process crashes correlated with stdin writes containing APC sequences
2. Alert on PNG format declarations (f=100) in terminal input streams
3. Track process creation and stdin redirection patterns to Kitty instances
4. Implement YARA rules to detect malicious APC graphics protocol payloads in network traffic
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تقوم بتشغيل إصدارات Kitty 0.46.2 وما دونها باستخدام أدوات جرد الأصول والكشف عن نقاط النهاية
2. تقييد الوصول إلى stdin لطرفيات Kitty للعمليات الموثوقة فقط؛ تطبيق مبدأ أقل امتياز
3. تعطيل دعم بروتوكول APC للرسومات إذا لم يكن مطلوباً (تكوين Kitty مع تعطيل الرسومات)
4. مراقبة أعطال الطرفية غير المتوقعة والربط مع أوامر بروتوكول APC في السجلات

إرشادات التصحيح:
1. الترقية إلى إصدار Kitty 0.47.0 أو أحدث فوراً عند توفره
2. بالنسبة للأنظمة غير القادرة على التصحيح فوراً، تطبيق تقسيم الشبكة لتحديد مصادر الإدخال غير الموثوقة
3. نشر قائمة بيضاء للتطبيقات لمنع العمليات غير المصرح بها من الكتابة إلى stdin الطرفية

الضوابط البديلة:
1. تطبيق التحقق من صحة الإدخال والتطهير لأي عملية تكتب إلى stdin في Kitty
2. استخدام مضاعفات الطرفية (tmux, screen) مع ضوابط الوصول المقيدة كطبقة وسيطة
3. تفعيل core dumps وتسجيل الأعطال للكشف عن محاولات الاستغلال
4. نشر قواعد IDS المستندة إلى المضيف للكشف عن أوامر بروتوكول APC مع إعلانات تنسيق PNG (f=100)

قواعد الكشف:
1. مراقبة أعطال عملية Kitty المرتبطة بكتابات stdin تحتوي على تسلسلات APC
2. التنبيه على إعلانات تنسيق PNG (f=100) في تدفقات إدخال الطرفية
3. تتبع أنماط إنشاء العمليات وإعادة توجيه stdin إلى مثيلات Kitty
4. تطبيق قواعد YARA للكشف عن حمولات بروتوكول APC للرسومات الضارة في حركة المرور
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Information security policies and procedures ECC 2024 A.5.2.1 - Access control and authentication ECC 2024 A.6.2.1 - Vulnerability management and patching ECC 2024 A.7.1.1 - Cryptography and secure communications ECC 2024 A.8.1.1 - Incident detection and response
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Software and hardware inventory SAMA CSF PR.AC-1 - Access control and authentication mechanisms SAMA CSF PR.MA-2 - Address vulnerabilities and apply patches SAMA CSF DE.CM-1 - Monitor and detect anomalies SAMA CSF RS.MI-1 - Establish incident response procedures
🟡 ISO 27001:2022
ISO 27001:2022 A.5.1 - Policies for information security ISO 27001:2022 A.8.1 - Asset management ISO 27001:2022 A.8.2 - Data classification and handling ISO 27001:2022 A.12.6 - Capacity and resource management ISO 27001:2022 A.14.2 - Information security requirements in supplier relationships
📦 Affected Products / CPE 1 entries
kovidgoyal:kitty
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-122
EPSS0.04%
Exploit ✓ Yes
Patch ✗ No
Published 2026-05-19
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-122
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.