Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS
ID: a7428626-ba54-5043-9216-5bd2d993f6b9
STIX ID: report--a7428626-ba54-5043-9216-5bd2d993f6b9
Feed Name: cybersecurityNews.com
Threat Score
A critical RCE vulnerability (CVE-2026-3102) in the widely used ExifTool library can execute hidden shell commands embedded in an image's DateTimeOriginal metadata on macOS when ExifTool is run with the -n/--printConv flag; organizations should update to ExifTool 13.50, avoid processing untrusted images on production systems, and monitor for vulnerable embedded versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
