{"id":2844,"date":"2025-03-26T10:04:02","date_gmt":"2025-03-26T10:04:02","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/google-chrome-zero-day-vulnerability-exploited-by-hackers-in-the-wild\/"},"modified":"2025-03-26T10:04:02","modified_gmt":"2025-03-26T10:04:02","slug":"google-chrome-zero-day-vulnerability-exploited-by-hackers-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/google-chrome-zero-day-vulnerability-exploited-by-hackers-in-the-wild\/","title":{"rendered":"Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild"},"content":{"rendered":"<p>    Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has released an urgent security update for its Chrome browser after cybersecurity researchers at Kaspersky discovered a <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-windows-mmc-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerability<\/a> being actively exploited by sophisticated threat actors.\u00a0<\/p>\n<p>The vulnerability, identified as CVE-2025-2783, allowed attackers to bypass Chrome\u2019s sandbox protection through a logical error at the intersection of Chrome\u2019s security framework and the Windows operating system, essentially rendering the browser\u2019s protective measures ineffective.<\/p>\n<p>The zero-day vulnerability, tracked as CVE-2025-2783, was discovered in mid-March 2025 when Kaspersky\u2019s detection systems identified a wave of infections from previously unknown malware.\u00a0<\/p>\n<p>In all documented cases, infections occurred immediately after victims clicked on links in phishing emails, with the malicious websites opening in Google Chrome without requiring any additional user interaction.<\/p>\n<p>\u201cThe vulnerability CVE-2025-2783 really left us scratching our heads, as, without doing anything obviously malicious or forbidden, it allowed the attackers to bypass Google Chrome\u2019s sandbox protection as if it didn\u2019t even exist,\u201d noted Kaspersky researchers in their analysis.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Stop attacks before they start, powered by a 97% precise neural Network to <strong><a href=\"https:\/\/firstwatch.whoisxmlapi.com\/?utm_campaign=9753186-Cyber%20Security%20News&amp;utm_source=email&amp;utm_medium=paidemail&amp;utm_content=csn2_websitevisit\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Detect Cyber Attacks<\/a><\/strong><\/p>\n<p>According to Google\u2019s <a href=\"https:\/\/chromereleases.googleblog.com\/2025\/03\/stable-channel-update-for-desktop_25.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security bulletin<\/a>, technical examination revealed that the exploit leveraged an \u201cincorrect handle provided in unspecified circumstances in Mojo on Windows. \u201d\u00a0<\/p>\n<p>The vulnerability was classified as \u201cHigh\u201d severity, and Google acknowledged that exploits exist in the wild.<\/p>\n<p>The summary of the vulnerability is given below:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>Google Chrome for Windows (versions prior to 134.0.6998.177\/.178)<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Remote code execution and system compromise<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>User must click on a malicious link, typically delivered via phishing email<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>High Severity<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Operation ForumTroll Campaign<\/strong><\/h2>\n<p>The <a href=\"https:\/\/securelist.com\/operation-forumtroll\/115989\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">attack campaign<\/a>, dubbed \u201cOperation ForumTroll\u201d by Kaspersky, specifically targeted Russian media outlets, educational institutions, and government organizations.\u00a0<\/p>\n<p>The attackers sent personalized phishing emails disguised as invitations to a scientific and expert forum called \u201cPrimakov Readings\u201d.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfjmiYHuCnGWHta6wtLFbsex-7rN8zbaWVoX2yH8HtEZQQgF9phPv4zABam4_zcmat9WnJS8o-sXlP1kNu-MXuN1o5mE5wOMC5T5lKd-gg5JscBZcvs0wB9XYiBbqJA952Bw2Bjew?key=aS_569P18bbjjtLIrf8goWtA\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing Email<\/figcaption><\/figure>\n<\/div>\n<p>Each malicious link was personalized and had a short lifespan, making detection challenging. <\/p>\n<p>However, Kaspersky\u2019s exploit detection technologies successfully identified the zero-day exploit used to escape Chrome\u2019s sandbox.<\/p>\n<p>Researchers noted that the sophisticated nature of the attack suggests the involvement of a state-sponsored <a href=\"https:\/\/cybersecuritynews.com\/sandworm-apt-group-adds-new-wiper\/\" target=\"_blank\" rel=\"noreferrer noopener\">APT (Advanced Persistent Threat)<\/a> group whose primary goal appears to be espionage.<\/p>\n<p>Upon receiving Kaspersky\u2019s detailed report, Google quickly addressed the issue.  On March 25, 2025, Google released Chrome updates 134.0.6998.177 and 134.0.6998.178 for Windows users, including a vulnerability patch.<\/p>\n<p>The Extended stable channel has also been updated to version 134.0.6998.178 for Windows, with both updates set to roll out over the coming days and weeks.<\/p>\n<p>In its Stable Channel Update announcement, Google acknowledged Kaspersky researchers Boris Larin (@oct0xor) and Igor Kuznetsov (@2igosha) for reporting the vulnerability on March 20, 2025.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Exploitation Chain<\/strong><\/h2>\n<p>The exploit chain involved two components: the sandbox escape vulnerability, and a remote code execution exploit.<\/p>\n<p>While Kaspersky was unable to obtain the second exploit, patching the sandbox escape vulnerability effectively blocks the entire attack chain.<\/p>\n<p>Kaspersky products detect the exploits and malware with verdicts including:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXe2qbipwwz-27_yeSBnB_r18jFFK9R_UnbB0rI9VcWuthuf46gHzehlRUleYomOv5KzRJelIvkD8NDtNiLWBD7rZ2blzLEA1dOJ_dsbLMAmvRKl_i3xVexPcVwoZq5zY6fActr_?key=aS_569P18bbjjtLIrf8goWtA\" alt=\"\"><\/figure>\n<\/div>\n<p>The primary indicator of compromise identified was primakovreadings[.]info.<\/p>\n<p>Security experts strongly recommend Chrome users update their browsers immediately. <\/p>\n<p>The update will roll out automatically over the coming days and weeks, but users can manually check for updates by navigating to Chrome\u2019s settings menu, selecting \u201cAbout Chrome,\u201d and installing any available updates.<\/p>\n<p>Kaspersky advises against clicking on potentially malicious links and plans to publish a detailed technical report on the exploit once the majority of users have installed the updated browser version.<\/p>\n<p>As this incident demonstrates, even widely used modern browsers with multiple security layers can contain vulnerabilities that sophisticated attackers can exploit. Regular updates and cautious online behavior remain essential defenses against evolving cyber threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enrichment&amp;utm_content=plans&amp;utm_term=180325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-warns-of-chrome-zero-day-vulnerability-exploited\/\">Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-warns-of-chrome-zero-day-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild Google has released an urgent security update for its Chrome browser after cybersecurity researchers at Kaspersky discovered a zero-day vulnerability being actively exploited by sophisticated threat actors.\u00a0 The vulnerability, identified as CVE-2025-2783, allowed attackers to bypass Chrome\u2019s sandbox protection through a logical error at the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[768,129,63,163,131,517],"tags":[130],"class_list":["post-2844","post","type-post","status-publish","format-standard","hentry","category-chrome","category-cyber-security","category-cyber-security-news","category-google","category-vulnerability","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2844"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2844"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2844\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}