My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers

Yufan You, Jianjun Chen, Zhongguancun Laboratory, Qi Wang, Haixin Duan, Zhongguancun Laboratory

34th USENIX Security Symposium · Day 1

The ubiquitous ZIP file format, a foundational component for everything from office documents and Android applications to Java archives and browser extensions, harbors a pervasive and under-explored security vulnerability: **semantic gaps** between its numerous parsing implementations. This paper, "My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers," by Yufan You, Jianjun Chen, Qi Wang, and Haixin Duan from Tsinghua University and Zhongguancun Laboratory, presents a groundbreaking systematic study into these inconsistencies. The research unveils how seemingly minor differences in how various software interprets the ZIP specification can be weaponized by attackers to bypass critical security measures.

AI review

This is exactly what security research should look like: systematic, novel, and devastatingly practical. The Tsinghua team took a class of bugs everyone knew existed in an ad-hoc way and turned it into a comprehensive taxonomy with a fuzzer that actually works. Three CVEs, bounties from Gmail/Coremail/Zoho, and five real-world exploit chains that hit everything from secure email gateways to Spring Boot. Hard to argue with results.