CVE-2025-2783
Description
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
Summary dbcve.org
A vulnerability in the Mojo message-passing framework in Google Chrome on Windows allows a remote attacker to escape the sandbox security boundary by exploiting an incorrect handle provided in unspecified circumstances. The attacker can achieve this by tricking a user into opening a malicious file, potentially gaining elevated privileges outside the sandboxed context.
Mitigation
Update Google Chrome to version 134.0.6998.177 or later on all Windows systems. This is a high-severity sandbox escape vulnerability that warrants priority patching.