logo

ExifTool Vulnerability Lets Malicious Images Trigger macOS Code Execution

ID: 58435933-b6d9-5cf9-baff-5e867ebd4ab2

STIX ID: report--58435933-b6d9-5cf9-baff-5e867ebd4ab2

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** A critical remote-code-execution vulnerability (CVE-2026-3102) in ExifTool (<=13.49) allows crafted DateTimeOriginal metadata in images to execute shell commands on macOS when ExifTool is invoked with the -n/--printConv flag; ExifTool 13.50 fixes the issue. Organizations should immediately upgrade, verify embedded ExifTool libraries in third-party apps and scripts, and process untrusted images in sandboxed environments while monitoring for abnormal script execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.