What Happened

Kaspersky discovered CVE-2025-2783, a zero-day Chrome vulnerability exploited in Operation ForumTroll, a targeted espionage campaign. The flaw is an incorrect handle provided in unspecified circumstances in Mojo on Windows — a sandbox escape that allows attackers to break out of Chrome's renderer sandbox.

Attack Vector

Victims received phishing emails containing links to legitimate-looking conference invitation websites. Clicking the link and navigating to the page in Chrome triggered the exploit with no further user interaction. The exploit chain required only a single click.

Targets

  • Russian media organizations
  • Educational institutions
  • Government entities
Kaspersky assesses the campaign has APT-level sophistication consistent with state-sponsored activity.

Recommended Actions

  1. Update Chrome to 134.0.6998.177 or later immediately (Help > About Google Chrome)
  2. Enable Enhanced Safe Browsing in Chrome settings
  3. Consider restricting Chrome updates via enterprise policy if testing required, but prioritize this patch
  4. Alert users to be suspicious of conference invitation emails