Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Apr 17, 2025

CVE-2025-2783

High
EPSS 36.3%CISA KEV
Google/Chromium Mojo

Description

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EPSS — Exploit Probability

36.3%

Higher than 97.0% of all CVEs

Required Action

https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-2783

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
36.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Mar 27, 2025

Added to KEV

Mar 27, 2025

Remediation Due

Apr 17, 2025

Affected Product

Google

Chromium Mojo

View all Google CVEs