ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixed the first actively exploited Chrome zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-2783CVE-2024-10487

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10487
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

NVD description · AI analysis pending
8.8<1%
  • google chrome
CVE-2025-2783
Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783)

CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile).

Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails.

8.39% KEV
  • Google Chrome Windows versions prior to 134.0.6998.177
  • Google Chromium (Mojo IPC component) Windows builds prior to the 134.0.6998.177 fix, as listed by CISA (affected component: Google Chromium Mojo)
massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion)
Full article301 words · extracted from securityaffairs.com · click to collapse

Google fixed a flaw in the Chrome browser for Windows that was actively exploited in attacks targeting organizations in Russia.

Google has released out-of-band fixes to address a high-severity security vulnerability, tracked as CVE-2025-2783, in Chrome browser for Windows. The flaw was actively exploited in attacks targeting organizations in Russia.

The vulnerability is an incorrect handle provided in unspecified circumstances in Mojo on Windows. Kaspersky researchers Boris Larin (@oct0xor) and Igor Kuznetsov (@2igosha) reported the vulnerability on March 20, 2025.

Mojo is Google’s IPC library for Chromium-based browsers, managing sandboxed processes for secure communication. On Windows, it enhances Chrome’s security, but past vulnerabilities have enabled sandbox escapes and privilege escalation.

Google did not share details about the attacks that exploited this vulnerability or the identity of the threat actors behind them.

“Google is aware of reports that an exploit for CVE-2025-2783 exists in the wild.” reads the advisory published by Google. “The Stable channel has been updated to 134.0.6998.177/.178 for Windows which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.”

In October, Google patched another critical Chrome vulnerability, tracked as CVE-2024-10487, reported by Apple Security Engineering and Architecture (SEAR) on October 23, 2024.

The vulnerability is an out-of-bounds write issue that resides in the Dawn implementation.

Dawn is an open-source and cross-platform implementation of the WebGPU standard. More precisely it implements webgpu. h that is a one-to-one mapping with the WebGPU IDL. Dawn is meant to be integrated as part of a larger system and is the underlying implementation of WebGPU in Chromium.

It’s unclear if the vulnerability has been actively exploited in attacks in the wild.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Chrome zero day vulnerability)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/175862/hacking/google-fixed-first-chrome-zero-day-in-2025.html