Kaspersky GReAT disclosed CVE-2026-3102, a command injection flaw in ExifTool that can let a malicious image trigger arbitrary shell commands on macOS. The bug affects ExifTool 13.49 and earlier and was fixed in 13.50. According to the report, the issue lies in the SetMacOSTags function, where an unsanitized date value can reach a system() call that invokes /usr/bin/setfile, allowing shell interpretation of attacker-controlled metadata.
Exploitation requires a crafted workflow in which ExifTool is run with the -n flag, bypassing PrintConvInv date sanitization, and the -tagsFromFile feature is used to copy a malicious value from a permissive source tag such as DateTimeOriginal into FileCreateDate. The vulnerable path is specific to macOS, but successful exploitation can fully compromise the user account processing the image. The February patch replaced string-based command construction with argument-list execution and added a wrapper to preserve prior I/O redirection behavior while removing the shell injection risk.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky GReAT publicly disclosed CVE-2026-3102, a command injection vulnerability in ExifTool version 13.49 and earlier on macOS. The flaw allows arbitrary shell command execution when attacker-controlled metadata is processed via SetMacOSTags, particularly when ExifTool is used with the -n flag and -tagsFromFile.
ExifTool fixed CVE-2026-3102 in February 2026 with the release of version 13.50. The patch removed shell-interpreted string command construction in the vulnerable macOS SetMacOSTags code path and replaced it with safer argument-list execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.