CVE-2025-2783
KEVHIGH 8.3EPSS 9.2%
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS
- 9.16% chance of exploitation in the next 30 days, 95th percentile
- CISA KEV
- added 2025-03-27
- Published
- 2025-03-26
- Updated
- 2026-02-26
Proof-of-concept exploits (5)
- Alchemist3dot14/CVE-2025-278333★ · 2025-04-06
- byteReaper77/CVE-2025-27838★ · 2025-06-16
- ElianGonzi00/CVE-2025-2783
- bjrjk/CVE-2025-2783
- razureink/cve-2025-2783-chrome_sandbox_escape_reproduction