Hackers Exploiting Chrome Zero‑Day Vulnerability in the Wild
A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.
A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.
This campaign was first detected in March 2025 by the Threat Intelligence Department of Positive Technologies Expert Security Center (PT ESC). The attackers conducted phishing operations targeting Russian organizations, using emails disguised as event invitations. Clicking on embedded links redirected victims to malicious websites hosting the exploit.
The exploit allows a sandbox escape in Chrome and installs the Trinper backdoor malware without further user interaction. Investigations indicate similar campaigns have been ongoing since October 2024, utilizing decoy invitations to international conferences.
The attackers employ sophisticated techniques, including multi-layered loaders and custom encryption, to maintain persistence and evade detection.
CVE-2025-2783 is a high-severity vulnerability in Google Chrome’s Mojo component on Windows systems. Mojo is a runtime library for inter-process communication (IPC). The flaw results from providing an incorrect handle under unspecified circumstances, enabling remote attackers to escape Chrome’s sandbox through malicious files or websites.
Field Value
A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783 , is under active exploitation in cyber-espionage campaigns.
CVE ID CVE-2025-2783
Severity High
Affected Software Google Chrome (Windows) prior to 134.0.6998.177/.178
Google has released a patch for Chrome version 134.0.6998.177/.178 for Windows users in response to reports from Kaspersky and other researchers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-2783 to its Known Exploited Vulnerabilities Catalog, urging immediate updates.
Security experts recommend updating Chrome to the latest version and enabling automatic updates. Additionally, deploying robust endpoint protection with exploit detection capabilities is advised to mitigate the risk of future zero-day attacks.
The exploitation of CVE-2025-2783 underscores the threat posed by advanced persistent threat (APT) groups leveraging browser zero-days. The Team46/TaxOff campaign demonstrates the effectiveness of phishing, advanced malware delivery, and rapid exploitation of unpatched systems.
Organizations should remain vigilant, prioritize timely patching, and invest in layered security to defend against evolving threats.
Based on reporting by GBHackers.
