
7-Zip patches XZ-based remote code execution flaw
7-Zip released version 26.02 to fix a remote code execution vulnerability in XZ data processing that could be exploited via specially crafted archives, with a heap-based buffer overflow fixed by added boundary checks. Exploitation requires user interaction, and there’s no automatic update, so users must manually install the patch from 7-zip.org. No active exploits are reported yet, but phishing or social engineering could deliver malicious archives, as archive vulnerabilities have been exploited in the past.