Attackers exploited CVE-2025-2783, a Windows-specific Google Chrome sandbox-escape vulnerability, in Operation ForumTroll phishing campaigns targeting Russian media, education, and government organizations. Specially crafted links triggered exploitation when opened in Chrome. The flaw involves improper handle management in Chrome’s Mojo inter-process communication framework, enabling attackers to bypass the browser sandbox as part of an attack chain. Kaspersky researchers Boris Larin and Igor Kuznetsov reported the vulnerability to Google, which released a patch on March 25, 2025; Italy’s CSIRT subsequently warned of active exploitation.
Organizations should update Windows installations of Chrome to version 134.0.6998.177/.178 or newer, following Google’s security bulletin, and verify deployment across managed endpoints. Additional defenses include reducing phishing exposure and monitoring suspicious renderer-process behavior. Although the Italian advisory reported an online proof of concept, the Python example linked by SecureLayer7 is explicitly a simulation, not a demonstrated exploit; its detailed patch-diff claims are also unsupported by identifiable commits or actual diffs in the supplied material.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Google released Chrome 134.0.6998.177 with a fix for CVE-2025-2783. The Italian CSIRT advisory identifies Windows versions preceding 134.0.6998.177/.178 as affected and recommends updating.
The SecureLayer7 reference identifies March 25, 2025, as the disclosure date for CVE-2025-2783, a Chrome sandbox-escape vulnerability affecting Windows.
Italian CSIRT issued an advisory reporting active exploitation through phishing links and stating that a proof of concept was available online. The supplied advisory does not establish that the reported proof of concept successfully exploits the vulnerability.
Kaspersky researchers Boris Larin and Igor Kuznetsov discovered the Chrome Mojo vulnerability and reported it to Google. The flaw involved improper handle validation and management, allowing execution outside the browser sandbox.
Attackers exploited CVE-2025-2783 as a zero-day during Operation ForumTroll, targeting organizations in Russia’s media, education, and government sectors. Specially crafted phishing links enabled Chrome sandbox escape and arbitrary code execution on Windows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
blog.securelayer7.net
Open sourceacn.gov.it
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.