Threat reportVulnerabilityTL-2026-0539
ExifTool macOS Command Injection CVE-2026-3102 — Malicious Image Metadata Triggers system() Sink via Unsanitized FileCreateDate in SetMacOSTags
ExifTool macOS Command Injection CVE-2026-3102 (TL-2026-0539), also tracked as ExifTool SetMacOSTags Injection, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-05-20. It has no confirmed attribution, affects Phil Harvey (ExifTool) ExifTool, references 1 CVE (CVE-2026-3102), maps to 15 MITRE ATT&CK techniques (T1027, T1027.003, T1036.005), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0539
- Threat ID
- TL-2026-0539
- Also known as
- ExifTool SetMacOSTags Injection, FileCreateDate Command Injection
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- media, publishing, government, legal, technology, creative-agencies, ci-cd-pipelines
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in ExifTool macOS Command Injection CVE-2026-3102
Malware and tooling: ExifTool <=13.49 (macOS/Darwin build), exiftool (binary or embedded Perl library)
How ExifTool macOS Command Injection CVE-2026-3102 works
Kaspersky GReAT disclosed CVE-2026-3102, a command injection in ExifTool <=13.49 on macOS. An attacker stages a shell payload inside an image's DateTimeOriginal tag using the -n flag (skipping PrintConvInv sanitization), then copies it into FileCreateDate via -tagsFromFile, which routes the unsanitized value through SetMacOSTags into a system() call constructing /usr/bin/setfile. Successful exploitation yields arbitrary shell execution as the user invoking ExifTool. Patched upstream in 13.50 (commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7) by replacing string-form system() with argument-list form.
CVE-2026-3102 is an OS command injection vulnerability (CWE-77/CWE-78) in the SetMacOSTags function of lib/Image/ExifTool/MacOS.pm affecting ExifTool versions 13.49 and earlier on macOS (Darwin). Discovered by Lucas Tay of Kaspersky''s Global Research and Analysis Team (GReAT) in February 2026 as a regression-class issue traced from his prior work on CVE-2021-22204, the flaw enables arbitrary shell command execution at the privilege level of the user invoking ExifTool when processing an attacker-controlled image file.
Technical root cause: In the vulnerable SetMacOSTags code path, ExifTool builds the shell command string $cmd = "/usr/bin/setfile -d ''${val}'' ''${f}''" where $f (filename) is properly shell-escaped but $val (the date value) is interpolated unsanitized. The vulnerable branch is reached only when the processed tag matches MDItemFSCreationDate (Spotlight system attribute) or its internal alias $FileCreateDate. Because single quotes are not stripped or escaped in $val, an attacker can inject closing-quote and command-substitution sequences that break out of the wrapping quotes and execute arbitrary shell commands.
Exploit chain: (1) Direct assignment to FileCreateDate is rejected by ExifTool''s PrintConvInv filter, which validates date/time formatting. (2) The -n (alias -printConv) flag instructs ExifTool to skip PrintConvInv and accept raw values for any tag, bypassing input sanitization. (3) The attacker first writes a malformed value containing single quotes into a permissive source tag such as DateTimeOriginal (EXIF 0x9003) using -n. (4) The attacker then invokes ExifTool with -tagsFromFile to copy the staged source tag into FileCreateDate; this copy operation — and only this copy operation — triggers SetMacOSTags. (5) SetMacOSTags concatenates the tainted $val into the setfile command and passes it to Perl''s system() function, executing the injected shell payload. The publicly demonstrated trigger command is: exiftool -n -tagsFromFile evil_benign.jpg "-FileCreateDate<DateTimeOriginal" pwn.jpg. A staging command of the form: exiftool -n -DateTimeOriginal="<injected>" evil_benign.jpg primes the source tag.
Impact: An attacker who places a crafted JPEG, PNG, or other ExifTool-readable file into a victim macOS workflow (newsroom intake, asset management pipelines, CI image processors, photo organization apps, BYOD device handling shared media) can achieve arbitrary command execution as the workflow user. Because ExifTool is widely embedded as a library and as a CLI utility in macOS imaging pipelines, downstream impact includes credential theft, persistence implantation, data exfiltration, and lateral pivoting from the compromised host.
Patch (commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7, ExifTool 13.50): The maintainer abstracted the system call into a new System() wrapper that uses Perl''s argument-list system() form — system(''/usr/bin/setfile'', ''-d'', $val, $file) — eliminating shell interpolation entirely. The wrapper additionally redirects STDOUT/STDERR to /dev/null to preserve original output suppression behavior. This fix removes the need for manual escaping and closes the injection class.
Detection and hunting opportunities focus on: ExifTool process invocations carrying both -n and -tagsFromFile flags with -FileCreateDate as destination, child processes of exiftool/perl matching /bin/sh -c or /usr/bin/setfile with anomalous arguments, and macOS Unified Logs showing setfile invocations with unusual quoting. Versioning checks should confirm ExifTool 13.50 or later across asset management platforms, photo apps, and bundled library copies.
MITRE ATT&CK techniques used in TL-2026-0539
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Obfuscated Files or Information: Steganography; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1564 Hide Artifacts
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File
Discovery
T1082 System Information Discovery; T1518 Software Discovery
Initial Access
T1091 Replication Through Removable Media; T1566 Phishing; T1566.001 Spearphishing Attachment
Resource Development
T1587.004 Develop Capabilities: Exploits; T1588.005 Obtain Capabilities: Exploits; T1608.001 Stage Capabilities: Upload Malware
Affected products and versions in ExifTool macOS Command Injection CVE-2026-3102
- Phil Harvey (ExifTool) — ExifTool
Vulnerable versions: <=13.49 on macOS/Darwin
Fixed in: 13.50 - Apple — macOS (host platform required for vulnerable code path)
Vulnerable versions: any macOS version running ExifTool <=13.49
Fixed in: upgrade ExifTool to 13.50
Remediation for ExifTool macOS Command Injection CVE-2026-3102
Patches
- ExifTool 13.50 (upstream release): https://github.com/exiftool/exiftool/releases/tag/13.50
- Patch commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7 (lib/Image/ExifTool/MacOS.pm)
Immediate actions
- Upgrade ExifTool to 13.50 or later on all macOS systems
- Audit asset management platforms and photo apps for embedded ExifTool libraries — confirm bundled versions are 13.50+
- Block or quarantine untrusted image files at email and web gateways for macOS users until patched
- Disable ExifTool invocations that combine -n with -tagsFromFile in CI pipelines until verified patched
Workarounds
- Avoid invoking ExifTool with the -n / -printConv flag on attacker-controllable inputs
- Avoid -tagsFromFile copy operations into FileCreateDate when processing untrusted images
- Wrap ExifTool invocations behind a parser that rejects images whose DateTimeOriginal or CreateDate tags contain single quotes, backticks, $( ), or shell metacharacters
- Restrict ExifTool to non-macOS hosts where the SetMacOSTags code path is unreachable
Longer-term hardening
- Isolate processing of untrusted media files in sandboxed VMs or dedicated hosts with no network egress
- Adopt least-privilege service accounts for image processing pipelines; do not run ExifTool as root or as a user with broad keychain access
- Enforce software composition analysis (SCA) on macOS build artifacts to catch outdated ExifTool copies bundled inside third-party apps
- Deploy macOS EDR with execution telemetry covering perl/exiftool/setfile invocations and shell child-process detection
CVEs associated with ExifTool macOS Command Injection CVE-2026-3102
Weaknesses (CWE) in ExifTool macOS Command Injection CVE-2026-3102
Timeline of ExifTool macOS Command Injection CVE-2026-3102
- CVE-2021-22204 disclosed: prior ExifTool eval-sink command injection that inspired Lucas Tay''s audit of adjacent sanitization routines.
- Kaspersky GReAT researcher Lucas Tay identifies CVE-2026-3102 while auditing ExifTool input validation paths similar to CVE-2021-22204.
- ExifTool 13.50 released with commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7 abstracting the vulnerable system() call into an argument-list System() wrapper.
- CVE-2026-3102 published by VulDB / NVD with CVSS 3.1 base 8.8 (HIGH) and CWE-77/CWE-78 weakness classification.
- NVD completes secondary analysis; vulnStatus set to Analyzed with CPE coverage for ExifTool <=13.49.
- Threadlinqs Intelligence publishes TL-2026-0539 with full MITRE mapping, IOCs, and detection coverage.
- Kaspersky Securelist publishes full technical writeup with reproduction steps, payload staging technique, and patch analysis.
- As of 2026-05-29, CVE-2026-3102 (ExifTool macOS SetMacOSTags command injection) is fixed in ExifTool 13.50 (Feb 2026), NVD-Analyzed at 8.8 HIGH, with only a public PoC and no in-the-wild exploitation or CISA KEV listing. Risk now confined to unpatched or bundled ExifTool copies <=13.49 reached via the non-default -n/-tagsFromFile flag chain.
Sources cited for ExifTool macOS Command Injection CVE-2026-3102
- How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
- NVD CVE-2026-3102
- ExifTool upstream repository
- Patch commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7
- ExifTool 13.50 release notes
- VulDB entry id.347528
- VulDB exploit submission 758146
- Related n-day reference: CVE-2021-22204 ExifTool eval injection
Detection coverage for TL-2026-0539
As of 2026-05-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0539 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.