This is a sandbox escape vulnerability in Google Chrome requiring a malicious file to be opened by a user. While it has a high CVSS score and is in CISA KEV, it affects a client application (browser) rather than a server application, making it unsuitable for direct internet exploitation via T1190.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-03-26
Added to CISA KEV: 2025-03-27 1 DAY BETWEEN CVE AND KEV
CVE-2025-2783 is a high-severity security vulnerability in Google Chrome on Windows that allowed for a sandbox escape [1].
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a ... CVE-2025-2783 Detail Description Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.699β¦
CVE-2025-2857 Detail. Description. Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escapeβ¦
This project is a research-oriented and educational simulation designed to demonstrate the concept of a sandbox escape vulnerability within Google Chrome ...
We were able to catch a 0-day Google Chrome sandbox escape exploit that was recently used in a wave of targeted attacks as a part of 1-click attack chain.
This repository contains a full-chain exploit implementation for CVE-2025-2783. The vulnerability resides in Chromium's Ipcz communication layer, allowing an attacker to achieve sandbox escape and arbitrary code execution from a restricted renderer process.