logo

CVE-2026-3102: The Photo That Pwns Your Mac

ID: c8b51be6-da5f-5d29-9106-ed950f73d5f5

STIX ID: report--c8b51be6-da5f-5d29-9106-ed950f73d5f5

Feed Name: NoHackie

Threat Score
80/100

Date Published: 2026-03-09

Date Updated: 2026-04-19

...
...

CVE-2026-3102 is a macOS-specific remote code execution vulnerability in ExifTool (fixed in v13.50) that allows shell commands embedded in image metadata DateTimeOriginal to execute when ExifTool is invoked with the -n/--printConv flag; it endangers automated, unattended image-processing pipelines and bundled/embedded copies of ExifTool and can be used to deploy stealthy trojans or infostealers. Immediate actions: update ExifTool to 13.50+, audit for embedded copies, remove or scope the -n flag, isolate untrusted file processing, and monitor for anomalous child processes and outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.