CVE-2025-2783Active Exploitation(google / chrome)

CRITICALCVSS 8.3 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-17. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 3d ago at 1 mentions (2026-03-05); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
chromewindows

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-05: 1Mentions · 2026-04-01: 1Mentions · 2026-04-14: 1Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Active Exploitation · 2026-03-05: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-14: 103-0504-0104-1410-01
Signal classification3 categories
Active Exploitation
133.3%
Exploit
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-051
Active Exploitation1
2026-04-011
Exploit1
2026-04-141
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab

    Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.

    0000047
    143 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2025-2857 | CVSS 10.0 Firefox sandbox escape on Windows. Compromised child process can escalate privileges. Patch NOW: Firefox 136.0.4, ESR 128.8.1, ESR 115.21.1 Similar to exploited Chrome vuln CVE-2025-2783 #CVE #PatchNow #ThreatIntel https://t.co/RvgvAK1bMG

    Post summary

    The tweet announces a critical Firefox vulnerability (CVE‑2025‑2857) and urges users to apply the latest patches, highlighting a Windows sandbox escape that can lead to privilege escalation.

    00000150
    25 followersView on X
  • aron4@aron_four
    Exploit

    Exploit for CVE-2025-2783 (Chrome sandbox escape bug in ipcz). Technical writeup coming soon. https://github.com/aronfour/CVE-2025-2783

    Post summary

    The text announces an available exploit for CVE‑2025‑2783, referencing a GitHub repository that likely contains exploit code, while making no claims of active exploitation or available patches.

    00000266
    1 followersView on X
  • LC@LCRootAc
    Active Exploitation

    Falha grave no Chrome (CVE-2025-2783) está sendo explorada. Google lançou atualização de emergência. Atualize agora para se proteger! Saiba mais no blog. #segurancadigital #chrome

    Post summary

    CVE-2025-2783 is being actively exploited in the wild, prompting Google to release an emergency patch that users should apply immediately.

    0000054
    85 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
OSmicrosoftwindows---

Explore more