CVE-2026-3102
CVSS 6.3 MEDIUM: a vulnerability was determined in exiftool up to 13.49 on macOS. EPSS 4% (89th percentile).
Vulnerabilities & Exploits
ExifTool on macOS is not just reading metadata here. A malicious image can turn into shell commands executed as the user who invokes ExifTool, and that risk extends to apps that embed the library rather than only people who run the tool directly.
Kaspersky GReAT found CVE-2026-3102 in ExifTool 13.49 and earlier and says it was patched in February 2026. The flaw is a string-escaping failure in a metadata parsing path that lets hidden instructions in image metadata reach a command-execution sink.
The practical blast radius is broader than a single utility install. Any macOS workflow that ingests untrusted images through ExifTool inherits the same command-execution risk, even when the host app never intended to run shell code.
1 source · May 20
CVSS 6.3 MEDIUM: a vulnerability was determined in exiftool up to 13.49 on macOS. EPSS 4% (89th percentile).
Kaspersky Securelist
How a single image takes control of a Mac
We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
originalPart of the PlainSec briefing for 2026-05-21
Every edition of this story: Malicious Images Can Trigger Commands in ExifTool on macOS