Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploiting Chrome Zero‑Day Vulnerability in the Wild

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.

This campaign was first detected in March 2025 by the Threat Intelligence Department of Positive Technologies Expert Security Center (PT ESC). The attackers conducted phishing operations targeting Russian organizations, using emails disguised as event invitations. Clicking on embedded links redirected victims to malicious websites hosting the exploit.

The exploit allows a sandbox escape in Chrome and installs the Trinper backdoor malware without further user interaction. Investigations indicate similar campaigns have been ongoing since October 2024, utilizing decoy invitations to international conferences.

The attackers employ sophisticated techniques, including multi-layered loaders and custom encryption, to maintain persistence and evade detection.

CVE-2025-2783 is a high-severity vulnerability in Google Chrome’s Mojo component on Windows systems. Mojo is a runtime library for inter-process communication (IPC). The flaw results from providing an incorrect handle under unspecified circumstances, enabling remote attackers to escape Chrome’s sandbox through malicious files or websites.

Field Value

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.
Joseph Cain · Thehackingpost

CVE ID CVE-2025-2783

Severity High

Affected Software Google Chrome (Windows) prior to 134.0.6998.177/.178

Google has released a patch for Chrome version 134.0.6998.177/.178 for Windows users in response to reports from Kaspersky and other researchers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-2783 to its Known Exploited Vulnerabilities Catalog, urging immediate updates.

Advertisement

Security experts recommend updating Chrome to the latest version and enabling automatic updates. Additionally, deploying robust endpoint protection with exploit detection capabilities is advised to mitigate the risk of future zero-day attacks.

The exploitation of CVE-2025-2783 underscores the threat posed by advanced persistent threat (APT) groups leveraging browser zero-days. The Team46/TaxOff campaign demonstrates the effectiveness of phishing, advanced malware delivery, and rapid exploitation of unpatched systems.

Organizations should remain vigilant, prioritize timely patching, and invest in layered security to defend against evolving threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories