7-Zip version 26.02 addresses a remote code execution vulnerability tracked as CVE-2026-14266 that stems from a heap-based buffer overflow when processing specially crafted XZ-compressed data. An attacker can trigger the flaw if a user opens a malicious archive or visits a page delivering a crafted XZ payload, allowing arbitrary code to run with the privileges of the logged-in user. The issue was disclosed by researcher Landon Peng and detailed in a Zero Day Initiative advisory, with the patch adding checks to prevent the decoder from writing beyond available buffer space. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!