logo

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

ID: e5b435d7-2ac8-5c29-8532-533cdbead1a5

STIX ID: report--e5b435d7-2ac8-5c29-8532-533cdbead1a5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical remote code execution vulnerability (CVE-2026-3102) in ExifTool for macOS allows attackers to hide shell commands inside the DateTimeOriginal EXIF field that execute when files are processed with the -n/--printConv flag; Kaspersky disclosed the issue and ExifTool 13.50 contains the fix, with organizations urged to update, audit embedded copies, and isolate processing of untrusted images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.