New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Asset Info
CreatorN/A
Registration TimeLoading...
RegistrarThe Hacker News
Capture TimeLoading...
GeolocationN/A
File TypeJPEG
Source TypedigitalUpload
Details
Abstract
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.
The overflow lets an attacker "execute code in the context of the current process," per the
LicenseN/A
Used Bythehackernews.com...
Mining PreferenceN/A
Integrity Proof