logo

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

ID: a7428626-ba54-5043-9216-5bd2d993f6b9

STIX ID: report--a7428626-ba54-5043-9216-5bd2d993f6b9

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical RCE vulnerability (CVE-2026-3102) in the widely used ExifTool library can execute hidden shell commands embedded in an image's DateTimeOriginal metadata on macOS when ExifTool is run with the -n/--printConv flag; organizations should update to ExifTool 13.50, avoid processing untrusted images on production systems, and monitor for vulnerable embedded versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.