PT-2025-49319 · Rarlab · Rar App+1

Lu1U

·

Published

2025-12-05

·

Updated

2025-12-12

·

CVE-2025-14111

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rarlab RAR App versions up to 7.11 Build 127
Description A security issue exists in the component com.rarlab.rar of Rarlab RAR App on Android. This allows for path traversal, potentially enabling remote attacks. Exploitation is considered highly complex and difficult, but the exploit has been publicly disclosed. The issue specifically affects RAR for Android and does not impact WinRAR or Unix RAR versions.
Recommendations Upgrade to version 7.20 build 128 to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-14111

Affected Products

Rar App
Air For Android