Vulnerabilities & Exploits

Malicious Images Can Trigger Commands in ExifTool on macOS

ExifTool on macOS is not just reading metadata here. A malicious image can turn into shell commands executed as the user who invokes ExifTool, and that risk extends to apps that embed the library rather than only people who run the tool directly.

Kaspersky GReAT found CVE-2026-3102 in ExifTool 13.49 and earlier and says it was patched in February 2026. The flaw is a string-escaping failure in a metadata parsing path that lets hidden instructions in image metadata reach a command-execution sink.

The practical blast radius is broader than a single utility install. Any macOS workflow that ingests untrusted images through ExifTool inherits the same command-execution risk, even when the host app never intended to run shell code.

1 source · May 20

CVE-2026-3102

NVD KEV

CVSS 6.3 MEDIUM: a vulnerability was determined in exiftool up to 13.49 on macOS. EPSS 4% (89th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-21

Every edition of this story: Malicious Images Can Trigger Commands in ExifTool on macOS

More from today