Out-of-Bounds Read Flaw in Matthias-Wandel jhead EXIF Parsing Component
CVE-2026-90681
Key Information:
- Vendor
Matthias-wandel
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-90681?
A vulnerability has been discovered in the Matthias-Wandel jhead software, specifically in the Get16u function located in the exif.c file related to EXIF Parsing. This weakness allows for an out-of-bounds read condition, potentially leading to unauthorized access to sensitive information. The vulnerability requires local access for exploitation, and an exploit has been publicly shared, highlighting the urgency for users to address this issue. Despite being alerted early through an issue report, the developers have yet to respond, raising concerns over timely remediation.
Affected Version(s)
jhead 3.0
jhead 3.1
jhead 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
