A path traversal flaw discovered in July 2025 that allows attackers to drop malicious files into sensitive system folders (like the Startup folder) when an archive is opened.
The "insidious" nature of these RAR files stems from their ability to bypass traditional user caution: insidous.rar
A high-severity flaw that spoofed file extensions, hiding executables behind benign names like .jpg or .pdf . A path traversal flaw discovered in July 2025