CVE-2026-3102
CVSS 6.3 MEDIUM: a vulnerability was determined in exiftool up to 13.49 on macOS. EPSS 3% (86º percentile).
Vulnerabilità ed exploit
ExifTool su macOS qui non si limita a leggere i metadati. Un’immagine malevola può trasformarsi in comandi shell eseguiti come l’utente che richiama ExifTool, e tale rischio si estende alle app che incorporano la libreria anziché solo alle persone che eseguono direttamente lo strumento.
1 fonte · 20 mag
CVSS 6.3 MEDIUM: a vulnerability was determined in exiftool up to 13.49 on macOS. EPSS 3% (86º percentile).
Kaspersky Securelist
How a single image takes control of a Mac
We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
originalePart of the PlainSec briefing for 2026-05-20
Every edition of this story: Immagini Malevole Possono Attivare Comandi in ExifTool su macOS