Critical ExifTool Flaw Allow Attackers to Compromise Your Mac Via Malicious Image
ID: f2cbc782-c44f-5d47-82a8-8bb6db0b14e3
STIX ID: report--f2cbc782-c44f-5d47-82a8-8bb6db0b14e3
Feed Name: Cyber Press
A critical command-injection vulnerability (CVE-2026-3102) in ExifTool (<=13.49) lets an attacker embed shell commands in image metadata (e.g., DateTimeOriginal) that, when processed on macOS with the -n/--printConv flag, are passed unsanitized to system(), enabling arbitrary code execution. Kaspersky GReAT discovered the flaw and the maintainer released ExifTool 13.50 to fix it by switching to a list-form system() invocation; proof-of-concept exploit code is public, so administrators should update affected macOS systems, audit embedded ExifTool copies, sandbox untrusted file processing, and enforce endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
