HIGH

CVE-2025-2783

Google Chrome 2025-03-26 CVSS v3.1
CVSS
8.3
KEV

Description

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

Summary dbcve.org

A vulnerability in the Mojo message-passing framework in Google Chrome on Windows allows a remote attacker to escape the sandbox security boundary by exploiting an incorrect handle provided in unspecified circumstances. The attacker can achieve this by tricking a user into opening a malicious file, potentially gaining elevated privileges outside the sandboxed context.

Mitigation

Update Google Chrome to version 134.0.6998.177 or later on all Windows systems. This is a high-severity sandbox escape vulnerability that warrants priority patching.

EPSS Score

9.24%
Probability of exploitation in next 30 days
95.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE