English

Images & photos · Image Metadata Privacy Tool

The Hidden Thumbnail Inside Your JPEG: How the EXIF IFD1 Preview Works

· How it works

exif image-privacy file-formats

A large edited photograph beside a smaller thumbnail enclosed inside an EXIF block
Original ToolAcre vector illustration

Most camera JPEGs carry a second, small copy of the picture inside their EXIF block, and editors that crop or blur the main image do not always regenerate it, so the thumbnail can still show what you removed. This post explains where it lives and how stripping deals with it.

The crop that was still visible — the problem of an unchanged thumbnail surviving a careful edit of the main image

A cropped or blurred main image can still carry an older preview inside its EXIF block. That creates a second-picture risk: the visible pixels may reflect the edit while the embedded thumbnail reflects an earlier state. The repository does not claim that every camera or editor creates this mismatch, but it treats a thumbnail inside EXIF as private container data that leaves with the block.

Where the thumbnail lives — IFD1, the JPEGInterchangeFormat and JPEGInterchangeFormatLength tags, and the small JPEG embedded inside the APP1 segment

TIFF directory chains can include IFD1, commonly used for a thumbnail and fields that locate its bytes. It sits inside the EXIF payload rather than beside the JPEG’s main entropy-coded scan. The important product boundary is structural: the metadata reader follows IFD0 plus Exif and GPS sub-directories and stops, so the thumbnail’s own fields and pixels are not displayed.

Why cameras include it — fast previews on camera screens and in file browsers, and the DCF convention of a small fixed-size preview

A small preview gives software a quick image without decoding the full photograph. That convenience also means there can be more than one representation in one file. The tool’s known-gaps list states the narrow guarantee accurately: a thumbnail embedded inside an EXIF block is removed with that block, while thumbnails stored elsewhere in a container the parser does not understand are not covered.

How editors get it wrong — software that rewrites pixels but copies the EXIF block through unchanged, leaving a stale preview

Editors can update the main picture and leave metadata structures untouched, or export a fresh file that handles them differently. The repository does not inspect editor histories, so it cannot identify which application caused a stale preview. Treat the presence of EXIF as enough reason to preserve the original privately and create a cleaned sharing copy.

How this tool handles an IFD1 thumbnail without parsing it

The workbook heading said the parser finds IFD1, but the implementation explicitly does not chase IFD1 thumbnails. ToolAcre handles this risk through whole-block removal instead: JPEG APP1 Exif, PNG eXIf and WebP EXIF are dropped as units. That distinction prevents an unsupported preview-inspection capability from being implied.

Worked example: removing a cropped photo’s complete EXIF block

For a cropped photo, first inspect the ordinary fields the parser can read, then remove metadata and verify the cleaned bytes. Verification can confirm that no field readable by this parser remains; it cannot show a before-and-after thumbnail because the thumbnail was never decoded. The removal result is supported by the container rule, not by a thumbnail preview in the interface.

What this does not cover — previews stored in RAW files and inside proprietary MakerNote blocks are a separate problem

RAW, HEIC, TIFF and other unsupported formats can place previews and metadata in structures this tool does not rewrite. A thumbnail outside a supported EXIF block is also beyond the promise. Visible content, steganography and colour-profile description strings remain separate review concerns, so whole-block removal is not a universal image-sanitisation claim.

Takeaway: check the second picture too — the Image Metadata Privacy Tool removes the whole EXIF block, thumbnail included, without re-compressing the main image

Check the second picture by controlling the whole EXIF block, not by assuming the field table shows every embedded object. On a supported JPEG, PNG or WebP, removing that block also removes an EXIF-contained thumbnail without touching compressed main-image data. Keep the edited master and download a separate cleaned copy for sharing.