Executive brief
7-Zip is a popular file compression and archiving utility used to manage various file formats. A security flaw in how it handles XZ-compressed files could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to unauthorized access to personal data or the installation of harmful software.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in 7-Zip within the processing of XZ chunked data. The flaw is triggered during the decompression of specially crafted XZ-compressed data, leading to memory corruption. While categorized with a local attack vector in CVSS, the vulnerability is exploitable if a user opens a malicious file or visits a malicious page (User Interaction required). Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. The issue is fixed in version 26.02.
Affected products
- 7-Zip 7-Zip 26.01
Timeline
- 2026-06-05: other: Vulnerability reported to vendor
- 2026-07-15: advisory: Coordinated public release of advisory by ZDI
- 2026-07-15: patched: Fixed in version 26.02
- 2026-07-29: disclosed: NVD publication date