Junglewise Threat Intelligence

CVE-2025-2783: Google Chromium Mojo Sandbox Escape Vulnerability

CVE-2025-2783 · Severity: critical · CVSS 8.3 · Exploited in the wild · Published 2025-03-27

Technologies: Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium Mojo on Windows contains a sandbox escape vulnerability due to a logic error where an incorrect handle is provided under unspecified circumstances. A remote attacker can exploit this via a malicious file to escape the browser sandbox and execute code on the host system.

Affected products

  • Google Chrome < 134.0.6998.177
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2025-03-26: disclosed
  • 2025-03-26: patched: Fixed in Chrome version 134.0.6998.177
  • 2025-03-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-27: exploited

Related threats