Securelist Critical ExifTool Vulnerability (CVE-2026-3102) Threatens macOS Systems
Article Content
- •CVE-2026-3102 allows remote command execution on macOS via ExifTool.
- •The vulnerability affects ExifTool versions 13.49 and earlier, patched in 13.50.
- •Attackers can exploit this flaw by embedding malicious commands in image metadata.
A severe vulnerability in ExifTool (CVE-2026-3102) allows attackers to execute arbitrary shell commands on macOS systems by embedding malicious instructions in image file metadata. Discovered by Kaspersky's GReAT in February 2026, this flaw affects ExifTool versions 13.49 and earlier. Exploitation requires the use of the -n flag, enabling command injection via the SetMacOSTags function. The vulnerability has been publicly disclosed and poses a significant risk as it can be exploited remotely. Users are advised to upgrade to ExifTool version 13.50 to mitigate this risk. The flaw is linked to a previous vulnerability (CVE-2021-22204), showcasing ongoing issues with input validation in ExifTool. The potential for full system compromise makes this a critical security concern for macOS users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2021-22204 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…