Google says a well-known, already-patched WinRAR vulnerability (CVE-2025-8088) is in "widespread, active" use by government-backed threat actors linked to Russia and China, the company warned. The exploit was identified in July last year and posted to the National Vulnerability Database in August.
Google and other bodies have noted