Chrome Zero-Day Actively Exploited in Attacks by Mem3nt0 mori
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-2783 | Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783) CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile). Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails. | 8.3 | 9% | KEV |
| massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion) | |
| CVE-2025-2857 | Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1. NVD description · AI analysis pending | 10.0 | 2% |
| — |
Full article430 words · extracted from infosecurity-magazine.com · click to collapse
A critical zero-day flaw in Google Chrome, tracked as CVE-2025-2783, has been exploited in the wild as part of a targeted espionage campaign dubbed “Operation ForumTroll.”
According to new findings from Kaspersky, the attacks have been linked to the group known as Mem3nt0 mori, also referred to as ForumTroll APT, and appear to involve tools developed by the Italian spyware vendor Memento Labs.
Sophisticated Attack Chain
The exploitation began in March 2025, when victims received highly personalized phishing emails inviting them to the Primakov Readings forum.
Clicking on the short-lived malicious links led directly to infection, requiring no further user action. The attacks primarily targeted organizations in Russia and Belarus, including universities, research centers, financial institutions and government agencies.
Kaspersky’s analysis revealed that the attackers deployed a sandbox escape exploit to compromise Chrome and other Chromium-based browsers.
The flaw stemmed from a logical oversight in Windows’ handling of pseudo handles, allowing attackers to execute code in Chrome’s browser process.
Google swiftly patched the issue in version 134.0.6998.177/.178. Firefox developers later found a related issue in their browser, addressed as CVE-2025-2857.
Espionage Tools Linked to Memento Labs
Investigators traced the malicious toolkit used in Operation ForumTroll to 2022 campaigns attributed to Mem3nt0 mori.
These attacks deployed spyware called LeetAgent, capable of:
-
Executing shellcode and commands remotely
-
Running background keyloggers
-
Stealing files with extensions such as .docx, .xlsx, and .pdf
Further analysis uncovered the use of a more advanced spyware platform known as Dante, a commercial product developed by Memento Labs (formerly Hacking Team).
The Dante malware, which evolved from Hacking Team’s earlier Remote Control Systems suite, features extensive anti-analysis techniques and encrypted communications.
Implications and Industry Response
Kaspersky’s researchers concluded that Mem3nt0 mori leveraged Dante-based components in the ForumTroll campaign, marking the first observed use of this commercial spyware in the wild.
“This exploit genuinely puzzled us because it allowed attackers to bypass Google Chrome’s sandbox protection without performing any obviously malicious or prohibited actions,” the team said.
“This was due to a powerful logical vulnerability caused by an obscure quirk in the Windows OS.”
The discovery underscores ongoing risks from state-aligned and commercial surveillance vendors. Kaspersky urged security researchers to examine other software and Windows services for similar pseudo-handle vulnerabilities.
While Chrome’s new patch closes this loophole, the case highlights the persistent overlap between espionage actors and the global spyware market – a reminder that commercial surveillance tools continue to find new life in targeted cyber operations.
Image credit: CryptoFX / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chrome-zero-day-flaw-exploited/