# ExifTool macOS Command Injection CVE-2026-3102 — Malicious Image Metadata Triggers system() Sink via Unsanitized FileCreateDate in SetMacOSTags

> Kaspersky GReAT disclosed CVE-2026-3102, a command injection in ExifTool <=13.49 on macOS. An attacker stages a shell payload inside an image's DateTimeOriginal tag using the -n flag (skipping PrintConvInv sanitization), then copies it into FileCreateDate via -tagsFromFile, which routes the unsanitized value through SetMacOSTags into a system() call constructing /usr/bin/setfile. Successful exploitation yields arbitrary shell execution as the user invoking ExifTool. Patched upstream in 13.50 (commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7) by replacing string-form system() with argument-list form.

- **Published:** 2026-05-20T12:00:00Z
- **Last reviewed:** 2026-05-20T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0539
- **ID:** TL-2026-0539
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3102

## Description

CVE-2026-3102 is an OS command injection vulnerability (CWE-77/CWE-78) in the SetMacOSTags function of lib/Image/ExifTool/MacOS.pm affecting ExifTool versions 13.49 and earlier on macOS (Darwin). Discovered by Lucas Tay of Kaspersky''s Global Research and Analysis Team (GReAT) in February 2026 as a regression-class issue traced from his prior work on CVE-2021-22204, the flaw enables arbitrary shell command execution at the privilege level of the user invoking ExifTool when processing an attacker-controlled image file.

Technical root cause: In the vulnerable SetMacOSTags code path, ExifTool builds the shell command string $cmd = "/usr/bin/setfile -d ''${val}'' ''${f}''" where $f (filename) is properly shell-escaped but $val (the date value) is interpolated unsanitized. The vulnerable branch is reached only when the processed tag matches MDItemFSCreationDate (Spotlight system attribute) or its internal alias $FileCreateDate. Because single quotes are not stripped or escaped in $val, an attacker can inject closing-quote and command-substitution sequences that break out of the wrapping quotes and execute arbitrary shell commands.

Exploit chain: (1) Direct assignment to FileCreateDate is rejected by ExifTool''s PrintConvInv filter, which validates date/time formatting. (2) The -n (alias -printConv) flag instructs ExifTool to skip PrintConvInv and accept raw values for any tag, bypassing input sanitization. (3) The attacker first writes a malformed value containing single quotes into a permissive source tag such as DateTimeOriginal (EXIF 0x9003) using -n. (4) The attacker then invokes ExifTool with -tagsFromFile to copy the staged source tag into FileCreateDate; this copy operation — and only this copy operation — triggers SetMacOSTags. (5) SetMacOSTags concatenates the tainted $val into the setfile command and passes it to Perl''s system() function, executing the injected shell payload. The publicly demonstrated trigger command is: exiftool -n -tagsFromFile evil_benign.jpg "-FileCreateDate<DateTimeOriginal" pwn.jpg. A staging command of the form: exiftool -n -DateTimeOriginal="<injected>" evil_benign.jpg primes the source tag.

Impact: An attacker who places a crafted JPEG, PNG, or other ExifTool-readable file into a victim macOS workflow (newsroom intake, asset management pipelines, CI image processors, photo organization apps, BYOD device handling shared media) can achieve arbitrary command execution as the workflow user. Because ExifTool is widely embedded as a library and as a CLI utility in macOS imaging pipelines, downstream impact includes credential theft, persistence implantation, data exfiltration, and lateral pivoting from the compromised host.

Patch (commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7, ExifTool 13.50): The maintainer abstracted the system call into a new System() wrapper that uses Perl''s argument-list system() form — system(''/usr/bin/setfile'', ''-d'', $val, $file) — eliminating shell interpolation entirely. The wrapper additionally redirects STDOUT/STDERR to /dev/null to preserve original output suppression behavior. This fix removes the need for manual escaping and closes the injection class.

Detection and hunting opportunities focus on: ExifTool process invocations carrying both -n and -tagsFromFile flags with -FileCreateDate as destination, child processes of exiftool/perl matching /bin/sh -c or /usr/bin/setfile with anomalous arguments, and macOS Unified Logs showing setfile invocations with unusual quoting. Versioning checks should confirm ExifTool 13.50 or later across asset management platforms, photo apps, and bundled library copies.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1091 Replication Through Removable Media
- T1203 Exploitation for Client Execution
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1204.002 User Execution: Malicious File
- T1027 Obfuscated Files or Information
- T1027.003 Obfuscated Files or Information: Steganography
- T1564 Hide Artifacts
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1588.005 Obtain Capabilities: Exploits
- T1608.001 Stage Capabilities: Upload Malware
- T1587.004 Develop Capabilities: Exploits
- T1082 System Information Discovery
- T1518 Software Discovery

## Sources

- [How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)](https://securelist.com/exiftool-compromise-mac/119866/)
- [NVD CVE-2026-3102](https://nvd.nist.gov/vuln/detail/CVE-2026-3102)
- [ExifTool upstream repository](https://github.com/exiftool/exiftool/)
- [Patch commit e9609a9bcc0d32bd252a709a562fb822d6dd86f7](https://github.com/exiftool/exiftool/commit/e9609a9bcc0d32bd252a709a562fb822d6dd86f7)
- [ExifTool 13.50 release notes](https://github.com/exiftool/exiftool/releases/tag/13.50)
- [VulDB entry id.347528](https://vuldb.com/?id.347528)
- [VulDB exploit submission 758146](https://vuldb.com/?submit.758146)
- [Related n-day reference: CVE-2021-22204 ExifTool eval injection](https://nvd.nist.gov/vuln/detail/CVE-2021-22204)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0539
