logo

How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

ID: 1384c1d2-3676-547a-9530-c0f21e9cc2e1

STIX ID: report--1384c1d2-3676-547a-9530-c0f21e9cc2e1

Feed Name: Securelist by Kaspersky

Threat Score
65/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Lucas Tay

...
...

This report analyzes CVE-2026-3102, a command-injection vulnerability in ExifTool (<=13.49) on macOS that arises from unsanitized FileCreateDate metadata when copying tags with -tagsFromFile combined with the -n flag. The author shows how an attacker can store a payload in a writable EXIF tag (e.g., DateTimeOriginal), bypass formatting filters with -n, copy it into FileCreateDate to trigger a system() sink, and execute arbitrary commands as the invoking user; the issue is fixed in ExifTool 13.50 by replacing string-based system calls with an argument-list wrapper.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.