What Happened
Kaspersky discovered CVE-2025-2783, a zero-day Chrome vulnerability exploited in Operation ForumTroll, a targeted espionage campaign. The flaw is an incorrect handle provided in unspecified circumstances in Mojo on Windows — a sandbox escape that allows attackers to break out of Chrome's renderer sandbox.
Attack Vector
Victims received phishing emails containing links to legitimate-looking conference invitation websites. Clicking the link and navigating to the page in Chrome triggered the exploit with no further user interaction. The exploit chain required only a single click.
Targets
- Russian media organizations
- Educational institutions
- Government entities
Recommended Actions
- Update Chrome to 134.0.6998.177 or later immediately (Help > About Google Chrome)
- Enable Enhanced Safe Browsing in Chrome settings
- Consider restricting Chrome updates via enterprise policy if testing required, but prioritize this patch
- Alert users to be suspicious of conference invitation emails