CVE-2026-3102Disclosure(apple / exiftool)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch apple exiftool systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.

8.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-77CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exiftool
  • macos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 45 mentions across 20 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 29 signals
  • Disclosure: 23 classified signals
  • General: 9 classified signals
  • Peaked 4d ago at 12 mentions (2026-05-20); latest day: 1
  • 45 total mentions across 20 days

Affected systems

Products
exiftoolmacos

1 version affected across 2 products

Deep dive

Activity timeline45 mentions / 20d
036912Mentions · 2026-02-25: 3Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 6Mentions · 2026-03-10: 4Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-03-20: 1Mentions · 2026-04-22: 1Mentions · 2026-05-20: 12Mentions · 2026-05-21: 3Mentions · 2026-05-22: 1Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 1Exploit Tool / Code · 2026-03-09: 1Active Exploitation · 2026-05-20: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-02: 2Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-20: 4Patch / Workaround · 2026-05-21: 2Technical Details · 2026-02-25: 2Technical Details · 2026-03-02: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-09: 5Technical Details · 2026-03-10: 2Technical Details · 2026-03-16: 1Technical Details · 2026-03-20: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-20: 7Technical Details · 2026-05-21: 3Technical Details · 2026-05-22: 1Technical Details · 2026-05-25: 102-2503-0303-0503-0703-0903-1103-1604-2205-2105-2505-26
Signal classification4 categories
Disclosure
2351.1%
Patch
1124.4%
General
920.0%
Active Exploitation
24.4%
Referenced assets36 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-253
Disclosure2Patch1
2026-03-022
Disclosure1Patch1
2026-03-031
General1
2026-03-041
Disclosure1
2026-03-051
Patch1
2026-03-062
Patch2
2026-03-071
General1
2026-03-081
Disclosure1
2026-03-096
Disclosure6
2026-03-104
Disclosure1General2Patch1
2026-03-111
Disclosure1
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-03-201
Patch1
2026-04-221
Disclosure1
2026-05-2012
Active Exploitation1Disclosure4General4Patch3
2026-05-213
Active Exploitation1Disclosure1Patch1
2026-05-221
Disclosure1
2026-05-251
Disclosure1
2026-05-261
General1
Full discourse20 posts
  • Hermes Tool@Hermes_tooll
    Disclosure

    Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS https://ift.tt/ERTL3xM A serious security flaw has been found in ExifTool, a popular open-source tool used to read and edit image file metadata. Tracked as CVE-2026-3102, this vulnerability affects…

    Post summary

    A new critical CVE‑2026‑3102 flaw in ExifTool allows malicious images to trigger code execution on macOS, but the snippet lacks details on exploitation, patches, or PoC.

    111048213.6K
    2.3K followersView on X
  • Eugene Kaspersky@e_kaspersky
    Disclosure

    We're covering CVE-2026-3102 in ExifTool, discovered by GReAT experts: how malicious... metadata (!) in image files can lead to Mac hacking. Learn more: https://kas.pr/8ji9 https://t.co/btXdA79C49

    Post summary

    The tweet announces the discovery of CVE-2026-3102 in ExifTool, noting that malicious image metadata can facilitate Mac hacking, but provides no PoC, exploit code, active exploitation evidence, patch details, or specific technical depth.

    11413082.0K
    178.9K followersView on X
  • Kaspersky@kaspersky
    Patch

    Kaspersky GReAT researcher @malware_owl discovered CVE-2026-3102 — a command injection vulnerability in ExifTool (≤13.49) on macOS. A crafted image file with malicious metadata can trigger arbitrary code execution. Update to v13.50 now! #Kaspersky #GReAT #Cybersecurity #VulnerabilityResearch #OpenSource #InfoSec #macOS

    Post summary

    Kaspersky researcher discovered a command injection flaw in ExifTool on macOS, and users are advised to update to version 13.50 to mitigate the risk.

    0813187.8K
    312.6K followersView on X
  • Kaspersky España@KasperskyES
    Patch

    ⚠️ ¡Una simple imagen puede comprometer tu Mac! 💻 Hemos descubierto la vulnerabilidad CVE-2026-3102 en #ExifTool, una popular herramienta open-source utilizada para leer y editar metadatos de imágenes, vídeos y PDFs. El fallo permite ejecutar comandos arbitrarios en #macOS si se procesa una imagen manipulada con metadatos maliciosos. El exploit se esconde en campos de metadata (como DateTimeOriginal), por lo que la foto puede parecer completamente normal mientras ejecuta código en el sistema. Actualiza a ExifTool 13.50 o superior. ♻️ Todos los detalles en 👀👉 https://kas.pr/iz2z

    Post summary

    The post details CVE‑2026‑3102 in ExifTool, explaining how malicious metadata in an image can trigger arbitrary command execution on macOS, supplies a link to further details, and urges users to upgrade to version 13.50 or newer.

    0100138904
    27.1K followersView on X
  • Kaspersky España@KasperskyES
    Patch

    ⚠️ ¡Una simple imagen puede comprometer tu Mac! 💻 Hemos descubierto la vulnerabilidad CVE-2026-3102 en #ExifTool, una popular herramienta open-source utilizada para leer y editar metadatos de imágenes, vídeos y PDFs. El fallo permite ejecutar comandos arbitrarios en #macOS si se procesa una imagen manipulada con metadatos maliciosos. El exploit se esconde en campos de metadata (como DateTimeOriginal), por lo que la foto puede parecer completamente normal mientras ejecuta código en el sistema. Actualiza a ExifTool 13.50 o superior. ♻️ Todos los detalles en 👀👉 https://kas.pr/iz2z

    Post summary

    CVE-2026-3102 in ExifTool permits arbitrary command execution on macOS when processing malicious image metadata; updating to version 13.50 or newer mitigates the risk.

    0100144983
    27.0K followersView on X
  • Kaspersky España@KasperskyES
    Disclosure

    ⚠️ ¡Una simple imagen puede comprometer tu Mac! 💻 Hemos descubierto la vulnerabilidad CVE-2026-3102 en #ExifTool, una popular herramienta open-source utilizada para leer y editar metadatos de imágenes, vídeos y PDFs. El fallo permite ejecutar comandos arbitrarios en #macOS si se procesa una imagen manipulada con metadatos maliciosos. El exploit se esconde en campos de metadata (como DateTimeOriginal), por lo que la foto puede parecer completamente normal mientras ejecuta código en el sistema. Actualiza a ExifTool 13.50 o superior. ♻️ Todos los detalles en 👀👉 https://kas.pr/iz2z

    Post summary

    A newly discovered CVE-2026-3102 in ExifTool permits arbitrary command execution on macOS via malicious image metadata; users are urged to update to ExifTool 13.50 or later.

    04081392
    27.1K followersView on X
  • Kaspersky@kaspersky
    Patch

    Your next image file could execute code. Kaspersky GReAT discovered CVE-2026-3102, an ExifTool vulnerability allowing arbitrary command execution on macOS through malicious image metadata. No executable. No attachment warning. Just an image. Patch immediately if using ExifTool ≤13.49. https://kas.pr/wfr7 #CyberSecurity #macOS #Vulnerability

    Post summary

    Kaspersky’s GReAT uncovered CVE-2026-3102, an ExifTool flaw enabling arbitrary code execution on macOS through image metadata, and urges immediate patching for versions ≤13.49.

    120621.3K
    312.5K followersView on X
  • Nicolas Krassas@Dinosn
    General

    How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) https://securelist.com/exiftool-compromise-mac/119866/

    Post summary

    The brief text references ExifTool CVE‑2026‑3102 but does not provide evidence of a PoC, exploit, active attacks, a patch, or technical specifics, categorizing it as general information.

    020441.1K
    158.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Kaspersky discovers critical ExifTool flaw (CVE-2026-3102) enabling command injection via malicious image metadata on macOS 🇺🇸. Attackers can achieve RCE by embedding shell commands in EXIF data, then copying to FileCreateDate tag. Key technical details: • Affects ExifTool v13.49 and earlier on macOS systems only • Exploits unsanitized $val parameter in SetMacOSTags function's system() call • Requires -n flag (raw output mode) and -tagsFromFile feature to trigger vulnerable code path • Attack vector: inject single quotes in DateTimeOriginal tag, copy to FileCreateDate via `-tagsFromFile` operation • Bypasses PrintConvInv filter validation through raw value processing Attack methodology: • Craft malicious image with command injection payload in EXIF DateTimeOriginal field • Use `exiftool -n -tagsFromFile malicious.jpg "-FileCreateDate<DateTimeOriginal" target.jpg` • Payload executes when /usr/bin/setfile command processes unsanitized date string • Enables arbitrary command execution with user privileges DFIR artifacts: • Monitor /usr/bin/setfile process creation with unusual parent processes • Check ExifTool command line arguments for -n and -tagsFromFile flags • Examine EXIF metadata in suspicious images for non-standard datetime formats containing shell metacharacters Update to ExifTool v13.50+ immediately. Hunt for `exiftool -n -tagsFromFile` in command history and process logs. #DFIR_Radar

    Post summary

    The post announces the discovery of CVE-2026-3102, detailing its technical exploitation via EXIF metadata on macOS and recommending an immediate patch to ExifTool v13.50+.

    10062455
    1.8K followersView on X
  • Евгений Касперский@e_kaspersky_ru
    General

    Подробно рассказываем про уязвимость CVE-2026-3102 в ExifTool, обнаруженную экспертами GReAT: как вредоносные метаданные (!) в файлах изображений могут привести к взлому Mac: https://kas.pr/di1j https://t.co/qFMSyPwwsV

    Post summary

    The tweet briefly mentions CVE-2026-3102 in ExifTool, noting that malicious metadata in image files could compromise Macs, but it offers no PoC, exploit details, patches, or technical specifics.

    02041400
    24.2K followersView on X
  • Kaspersky Türkiye@KasperskyTR
    Patch

    Kaspersky GReAT; görsel, video ve PDF dosyalarındaki meta verileri okumak ve düzenlemek için kullanılan açık kaynaklı ExifTool yazılımında, macOs kullanıcılarını etkileyen CVE-2026-3102 kodlu kritik bir güvenlik açığı tespit etti.❗ Projenin geliştiricisi Phil Harvey, 7 Şubat'ta yayınlanan 13.50 sürümüyle söz konusu açığın giderildiğini duyururken Kaspersky, kullanıcıları bu ve benzeri güvenlik açıklarına karşı uyarıyor. Güvenlik açığına dair detaylar ve güvende kalma önerileri için kaydırın ➡️ Open Source Software Threats Data Feed hakkında daha fazla bilgi almak için ⬇️ 🔗 http://kaspersky.com/open-source-feed #Kaspersky #SiberGüvenlik #KurumsalGüvenlik

    Post summary

    The post alerts about CVE-2026-3102 in ExifTool and informs that the 13.50 release fixes the issue, but does not include PoC, exploit, or active exploitation details.

    11020141
    5.1K followersView on X
  • Anmol Singh Yadav@IamLucif3r_
    Disclosure

    New breakdown on CVE-2026-3102: An OS command injection vulnerability in ExifTool (up to v13.49) on macOS. Failing to sanitize metadata tags like DateTimeOriginal allows remote code execution via malformed PNGs. https://blog.anmolsinghyadav.com/i-sent-you-a-jpeg-now-i-own-your-mac-e49c5c27374f

    Post summary

    The passage announces a new OS command injection vulnerability in ExifTool on macOS (CVE‑2026‑3102), detailing how unsanitized metadata tags enable remote code execution, but it does not provide PoC code, active exploitation evidence, or a patch.

    01011134
    645 followersView on X
  • Case B – Blockchain Security Service@caseborg
    Patch

    #ExifTool on #macOS isn’t as safe as you think. CVE-2026-3102 lets a Mac get infected just by processing an image with malicious metadata. Update to version 13.50 and ensure all scripts use the latest ExifTool. One image can deliver malware without a click. https://t.co/705wB5iX7r

    Post summary

    The tweet informs users that CVE‑2026‑3102 can infect macOS via image metadata and advises updating ExifTool to version 13.50 to mitigate the vulnerability.

    0102063
    18 followersView on X
  • キタきつね@foxbook
    General

    ExifToolの脆弱性:画像がmacOSシステムに感染する仕組み The ExifTool vulnerability: how an image can infect macOS systems #Kaspersky (Mar 2) https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/

    Post summary

    The text cites a Kaspersky blog post about an ExifTool vulnerability (CVE‑2026‑3102) that can infect macOS via images, but offers no PoC, exploit details, active exploitation evidence, patches, or technical specifics.

    00012205
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3102 A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component P… https://www.cve.org/CVERecord?id=CVE-2026-3102

    Post summary

    A CVE‑2026‑3102 vulnerability was identified in exiftool up to version 13.49 on macOS, affecting the SetMacOSTags function in lib/Image/ExifTool/MacOS.pm.

    01020193
    56.6K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #AppSec #Threat_Research How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) https://securelist.com/exiftool-compromise-mac/119866 // critical RCE vulnerability in ExifTool ≤13.49 on macOS, exploitable via malicious image metadata

    Post summary

    The article describes a critical RCE in ExifTool versions up to 13.49 on macOS that can be triggered by malicious image metadata.

    00011187
    3.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical ExifTool flaw CVE-2026-3102 enables remote command execution on macOS via SetMacOSTags DateTimeOriginal field, patch by upgrading from 13.49 or earlier to 13.50. https://threatcluster.io/cluster/critical-exiftool-vulnerability-cve-2026-3102-allows-remote--62cbc48f

    Post summary

    The advisory announces that ExifTool CVE-2026-3102 permits remote command execution on macOS through the SetMacOSTags DateTimeOriginal field, and it can be remedied by upgrading to version 13.50.

    1001090
    274 followersView on X
  • Kaspersky España@KasperskyES
    Disclosure

    ⚠️ ¡Una simple imagen puede comprometer tu Mac! 💻 Hemos descubierto la vulnerabilidad CVE-2026-3102 en #ExifTool, una popular herramienta open-source utilizada para leer y editar metadatos de imágenes, vídeos y PDFs. El fallo permite ejecutar comandos arbitrarios en #macOS si se procesa una imagen manipulada con metadatos maliciosos. El exploit se esconde en campos de metadata (como DateTimeOriginal), por lo que la foto puede parecer completamente normal mientras ejecuta código en el sistema. Actualiza a ExifTool 13.50 o superior. ♻️ Todos los detalles en 👀👉 https://kas.pr/iz2z

    Post summary

    The post announces CVE-2026-3102 in ExifTool, describing an arbitrary command execution vulnerability via image metadata, and urges users to upgrade to version 13.50 or newer.

    01010415
    27.1K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ExifTool の脆弱性 CVE-2026-3102 が FIX:悪意の画像による RCE https://iototsecnews.jp/2026/03/09/critical-exiftool-flaw-lets-malicious-images-trigger-code-execution-on-macos/ macOS で発見された脆弱性 CVE-2026-3102 は、画像ファイルを開くだけでシステムを乗っ取りに至る恐れのあるものです。この問題の原因は、画像のメタデータを処理するオープンソース・ツール ExifTool にあります。具体的には、撮影日時などのデータ欄に埋め込まれた悪意の文字列を、OS への命令コマンドとして実行してしまう不備があります。 この脆弱性を悪用する攻撃者は、普通の写真に見えるファイルの内部 (DateTimeOriginalフィールドなど) に、隠しコマンドを仕込みます。この画像がmacOS 上の自動処理システムやフォレンジック・ツールで読み込まれると、ユーザーが気づかないうちにバックドアや情報窃取ウイルスがインストールされてしまいます。ご利用のチームは、ご注意ください。 #CVE20263102 #ExifTool #Vulnerability

    Post summary

    The piece announces CVE‑2026‑3102, a RCE flaw in ExifTool that can be triggered by malicious image metadata on macOS, warning of potential exploitation but lacking PoC, patch, or active exploitation details.

    02000167
    484 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical ExifTool Flaw Turns Harmless Images Into macOS Code Execution Triggers Researchers disclosed CVE-2026-3102, a critical ExifTool vulnerability that lets attackers hide shell commands inside image metadata and trigger code execution on macOS when files are processed with the -n flag. The issue matters because ExifTool is widely embedded in automated enterprise and forensic workflows, making seemingly safe image files a stealthy intrusion vector. 🎯 Target: Global/macOS Environments #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/exiftool-vulnerability/

    Post summary

    Researchers announced CVE-2026-3102, a critical ExifTool flaw that lets attackers embed shell commands in image metadata and trigger macOS code execution when files are processed with the -n flag.

    0101068
    273 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appexiftool_projectexiftool---

Explore more