None
EN
WinRAR exploit reportedly remains widely-used by China and Russia state actors despite patch — vulnerability allows malicious archives to deliver a hidden payload to Windows Startup folder
['Jowi Morales', 'Contributing Writer', 'Li Ken-Un', 'Social Links Navigation']
Latest from Tom's Hardware
According to the Google Threat Intelligence Group (GTIG), attackers take advantage of the CVE-2025-8088 critical vulnerability, which has since been addressed with the latest release of WinRAR, version 7.13.
CVE-2025-8088 describes a path traversal vulnerability in earlier versions of WinRAR, in which malicious actors create archives that have a hidden payload.
When the victim opens it, the payload is then surreptitiously delivered to a critical path.
Despite the ubiquity of fast internet and cloud storage, archiving apps like WinRAR, WinZip, and 7-Zip remain popular among some users.
So, if you have WinRAR installed on your system, it’s best that you upgrade it to the latest version to avoid becoming victimized through this attack vector.