Skip to content
COOEY

EXPOSURES › CVE-2025-2783

CVE-2025-2783

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-03-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-2783 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.

A sandbox escape vulnerability in Google Chromium's Mojo component allows attackers to potentially bypass security restrictions, impacting DIB organizations using Chromium-based browsers. This represents a significant compliance risk under NIST 800-171, requiring immediate patching and review of browser security configurations. Ensure all Chromium-based browsers are updated promptly.

Shame score — The vulnerability's active exploitation and potential for sandbox escape demonstrate a significant security oversight by a major vendor, impacting a widely used platform.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized