logo

Critical ExifTool Flaw Allow Attackers to Compromise Your Mac Via Malicious Image

ID: f2cbc782-c44f-5d47-82a8-8bb6db0b14e3

STIX ID: report--f2cbc782-c44f-5d47-82a8-8bb6db0b14e3

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-22

Author: Lucas Martin

...
...

A critical command-injection vulnerability (CVE-2026-3102) in ExifTool (<=13.49) lets an attacker embed shell commands in image metadata (e.g., DateTimeOriginal) that, when processed on macOS with the -n/--printConv flag, are passed unsanitized to system(), enabling arbitrary code execution. Kaspersky GReAT discovered the flaw and the maintainer released ExifTool 13.50 to fix it by switching to a list-form system() invocation; proof-of-concept exploit code is public, so administrators should update affected macOS systems, audit embedded ExifTool copies, sandbox untrusted file processing, and enforce endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.