Vulnerability intelligence
CVE-2026-3102
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
CVSS Score
7.5
High
EPSS — Exploit Probability
3.4%
Riskier than 88% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered May 20, 2026 · latest May 20, 2026
Coverage timeline
-
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)securelist.com · May 20, 2026