logo

Critical ExifTool Vulnerability Allows Malicious Images to Execute Code on macOS

ID: db2bb8af-f778-50d6-9f48-ab0bd1d55f57

STIX ID: report--db2bb8af-f778-50d6-9f48-ab0bd1d55f57

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** Kaspersky GReAT disclosed CVE-2026-3102, a macOS-specific ExifTool vulnerability that can execute embedded shell commands from image metadata (DateTimeOriginal) when ExifTool is run with -n/--printConv, enabling silent retrieval and execution of secondary payloads; organizations should update ExifTool and review automated media-processing workflows to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.