7-Zip 26.02 fixes a remote code execution flaw in its XZ decompression handling that could let attackers run arbitrary code through a specially crafted archive. Users should install the update manually from 7-zip.org, as there is no automatic updater, to reduce the risk of phishing-delivered attacks and future exploitation. #7Zip #LandonPeng #XZ
Keypoints
- 7-Zip 26.02 patches a remote code execution vulnerability.
- The flaw affects processing of XZ-compressed data.
- Specially crafted data could trigger a heap-based buffer overflow.
- Exploitation requires user interaction, such as opening a malicious archive.
- Users must manually update from the official 7-Zip website.