The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a critical zero-day vulnerability in Google Chrome that is actively being exploited in the wild. The vulnerability, identified as CVE-2025-2783, affects the Chromium-based browsers on Windows systems and poses a significant security risk to users and organizations. CVE-2025-2783 is a high-severity sandbox escape vulnerability in the Chromium Mojo framework, which is used by popular browsers such as Google Chrome, Microsoft Edge, and Opera. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. CISA strongly urges all users and organizations to update their Chrome browsers immediately to mitigate the risk. Consider deploying advanced security tools such as SIEM (Security Information and Event Management) solutions to enhance threat detection and response capabilities. The primary goal of the campaign appears to be espionage, highlighting the potential national security implications of this vulnerability. For federal agencies, CISA emphasizes adherence to the Binding Operational Directive (BOD) 22-01, which provides specific guidance for addressing known exploited vulnerabilities in cloud services. The flaw originates from a logic error that results in an incorrect handle being provided under specific circumstances, allowing attackers to bypass Chrome’s sandbox protections. Enable automatic updates for browsers to ensure prompt installation of future security patches. Update Google Chrome and other Chromium-based browsers to the latest version immediately. The agency also reminds users and organizations to remain vigilant and report any suspicious activities or potential compromises to the relevant authorities. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. Google has responded swiftly to the threat by releasing a patch for Chrome users on Windows.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 28 Mar 2025 03:00:17 +0000