logo

Critical ExifTool Vulnerability Allows Attackers to Compromise Macs via Single Malicious Image

ID: e226bb88-61c6-55a9-9336-9f565d5c1271

STIX ID: report--e226bb88-61c6-55a9-9336-9f565d5c1271

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Guru Baran

...
...

A critical ExifTool vulnerability (CVE-2026-3102) affecting macOS was discovered that permits arbitrary shell execution by embedding malicious payloads in image metadata and forcing ExifTool to copy unsanitized values into FileCreateDate via the -n and -tagsFromFile workflow; the issue was fixed in ExifTool 13.50 and organizations are advised to update, scan for embedded older versions, and isolate untrusted file processing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.