Critical ExifTool Vulnerability Allows Attackers to Compromise Macs via Single Malicious Image
ID: e226bb88-61c6-55a9-9336-9f565d5c1271
STIX ID: report--e226bb88-61c6-55a9-9336-9f565d5c1271
Feed Name: cybersecurityNews.com
Threat Score
A critical ExifTool vulnerability (CVE-2026-3102) affecting macOS was discovered that permits arbitrary shell execution by embedding malicious payloads in image metadata and forcing ExifTool to copy unsanitized values into FileCreateDate via the -n and -tagsFromFile workflow; the issue was fixed in ExifTool 13.50 and organizations are advised to update, scan for embedded older versions, and isolate untrusted file processing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
