A critical security vulnerability, identified as CVE-2025-8088, has been uncovered in WinRAR for Windows, which has already been actively exploited in phishing campaigns. Attackers can craft malicious archive files that stealthily place content in unauthorized areas on victims' systems, notably the Windows startup folder. To address this issue, WinRAR has released version 7.13 and subsequent updates. Given that WinRAR lacks an automatic update feature, it is highly recommended for all users to promptly visit the official website win-rar.com to download and install the latest version, thereby safeguarding their system security.