NearScrub

2026-07-25

The EXIF/GPS photo and document metadata leaks that actually happened

Most people who think about "metadata" at all think about it in the abstract — some invisible technical residue that doesn't really do anything. It does. A JPEG's EXIF block can carry GPS coordinates precise enough to put a pin on a specific pool chair; a Word or PowerPoint file's hidden properties can carry author names, computer usernames, and a revision history that outlives every "Accept All Changes" click. None of this is a hypothetical risk model — it has already put specific, named people in specific, documented trouble, in ways that are easy to find and verify. This post walks through three of those cases, what actually leaked and how, and what to check before your own photos or documents go out.

The one that got a fugitive arrested: John McAfee, 2012

In late 2012, anti-virus pioneer John McAfee was hiding from Belizean authorities and gave Vice Magazine an exclusive interview and photo. The photo Vice published still had its EXIF data intact — including the GPS coordinates the iPhone 4S had recorded at the moment of capture. Within hours, people online had extracted those coordinates and matched them to a specific restaurant and pool in Guatemala. McAfee was located and arrested there shortly after. He initially claimed the photo's metadata had been faked as a decoy; he later admitted, in his own blog post, that he was in fact in Guatemala. The incident is one of the most widely cited cautionary tales about EXIF GPS data precisely because every step of the chain — photo taken, uploaded with GPS intact, GPS extracted, location matched, person located — is on the public record.

The mechanism is mundane: most phone cameras write a GPSLatitude/GPSLongitude tag into every photo's EXIF block by default, because that's what makes "photos near me" and map-based photo apps work. It's a genuinely useful feature for a private photo library. It's a liability the moment that same file — unmodified — leaves your device.

The one that published a home address and a work schedule in one tweet

Two years earlier, in August 2010, MythBusters host Adam Savage posted a photo on Twitter of his car parked outside his house, captioned to the effect of heading off to work. The photo's EXIF still carried its geotag. Between the geotag and the caption, the post effectively announced his home's exact location and the fact that it would be empty starting at that moment. The incident became widely cited enough that it shows up years later in U.S. military geotagging-safety training material aimed at service members and their families, alongside law-practice and security-industry commentary — not because it caused a break-in, but because it's such a clean example of how two harmless-seeming pieces of information (where, and when nobody's home) combine into one that isn't harmless at all. The same combination — a location-tagged photo plus an obvious absence signal — is exactly what a marketplace listing photo, a moving-day post, or a vacation photo can recreate without anyone intending it.

The one that outed the authors of a government document

Photos aren't the only file type with this problem. In February 2003, the UK government published a document on Iraq's weapons programs — later nicknamed the "dodgy dossier" — that turned out to contain substantial passages lifted from a graduate student's thesis. Part of how that was proven so quickly: the published Word file still carried its own revision history and author metadata. Researchers examined the document's internal structure and found the edit trail intact, naming the government officials who had actually authored and revised the text — information the document's public content never stated. The dossier's plagiarism became a significant embarrassment for the government in the run-up to the Iraq war, and the metadata trail is the specific reason it was provable so fast, rather than a matter of stylistic suspicion.

The mechanism, again, is ordinary and not malicious by design: Office file formats (docx, xlsx, pptx, and their older/OpenDocument equivalents) store author name, company, last-modified-by username, and edit timestamps in dedicated property parts inside the file — separately from the visible document content, and untouched by "Accept All Changes," which only resolves visible tracked edits, not the underlying properties. A resume, a legal filing, a press release, or a leaked internal memo can all carry the actual author's name and machine username even after every visible trace of authorship has been edited out of the text itself.

Where this shows up today: marketplaces, rentals, and everyday sharing

The McAfee and Savage cases both involve public figures, but the same EXIF GPS tag sits in photos from an ordinary phone used for anything else: a secondhand-marketplace listing, a short-term rental photo set, a real-estate listing shot before a house is publicly for sale, a photo of a package on a doorstep. None of those situations require a public profile to matter — they just require the recipient of the photo to be someone you'd rather not hand your exact coordinates to. Some platforms strip GPS EXIF from photos on upload; many peer-to-peer sharing paths — messaging apps, marketplace listings hosted directly from a photo file, emailed attachments — don't, which means the file a buyer or stranger actually downloads can still carry the original tag even when the platform's own feed view doesn't show it.

What to actually check before sharing

The fix in all three cases above would have been the same one-step habit: strip the file's metadata before it leaves your device, not after someone else has already downloaded a copy. For photos, that means EXIF GPS tags, camera/device identifiers, and timestamps. For Office documents, it means author name, company, last-modified-by, and revision history — the exact fields that outed the dossier's writers. This is what NearScrub does: drop a JPEG, PNG, PDF, or Office file in, and it strips EXIF/GPS, XMP, IPTC, and hidden document properties entirely inside your browser — no upload, no server, nothing leaves your device in the process of removing the thing you didn't want leaving your device either. The file comes back clean, and the only person who ever saw the original metadata is you.

Sponsored
← NearScrub

This page shows ads only if you consent.