Critical ExifTool Vulnerability Lets Hackers Compromise Macs via Malicious Images
ID: 88b79341-dd0b-549f-aa88-43899d7ef6de
STIX ID: report--88b79341-dd0b-549f-aa88-43899d7ef6de
Feed Name: GBHackers
A critical ExifTool vulnerability (CVE-2026-3102) permits arbitrary command execution on macOS when crafted image metadata (e.g., FileCreateDate or MDItemFSCreationDate) is processed without proper sanitization—particularly when using the -n flag and -tagsFromFile workflows; ExifTool 13.50 fixes the issue by moving to argument-based system calls and adding a secure wrapper. Users should update to 13.50+, check for embedded/outdated copies, and process untrusted files in isolated environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
