Skip to content
COOEY

FAIL › dossier

Chromium Mojo

PRODUCT

· dossier confidence 20%

Chromium Mojo is a sandboxing component within the Chromium project that has suffered repeated high-severity remote code execution vulnerabilities, including two confirmed sandbox escapes that have been actively exploited in the wild.

PROFILE
CategorysoftwareWhat they doChromium Mojo is a software component within the Chromium project that provides a sandboxing mechanism for browser processes. Websitehttps://chromium.googlesource.com/chromium/src/ ↗
SECURITY POSTURE

The security posture is compromised by a history of high-severity remote code execution (RCE) vulnerabilities in the Mojo sandbox, with at least two confirmed escapes actively exploited in the wild.

Notable failures
  • CVE-2025-2783: Mojo sandbox escape actively exploited in the wild
  • CVE-2022-3075: Mojo sandbox escape via crafted HTML page
Patterns: repeated Mojo sandbox escape vulnerabilities
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-03-27 CVE-2025-2783 high A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.
2022-09-08 CVE-2022-3075 high Google Chromium Mojo allows remote attackers to escape the sandbox via a crafted HTML page.
Open questions: Exact founding date of the Mojo component · Specific size of the Chromium Mojo development team
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:55:16.063880+00:00