Executive brief
Google Chromium Mojo on Windows contains a sandbox escape vulnerability due to a logic error where an incorrect handle is provided under unspecified circumstances. A remote attacker can exploit this via a malicious file to escape the browser sandbox and execute code on the host system.
Affected products
- Google Chrome < 134.0.6998.177
- Microsoft Edge
- Opera Software Opera
Timeline
- 2025-03-26: disclosed
- 2025-03-26: patched: Fixed in Chrome version 134.0.6998.177
- 2025-03-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-27: exploited