ExifTool on macOS is not just reading metadata here. A malicious image can turn into shell commands executed as the user who invokes ExifTool, and that risk extends to apps that embed the library rather than only people who run the tool directly. Kaspersky GReAT found CVE-2026-3102 in ExifTool 13.49 and earlier and says it was patched in February 2026. The flaw is a string-escaping failure in a metadata parsing path that lets hidden instructions in image metadata reach a command-execution sink. The practical blast radius is broader than a single utility install. Any macOS workflow that ingests untrusted images through ExifTool inherits the same command-execution risk, even when the host app never intended to run shell code.
Part of the PlainSec briefing for 2026-05-21