CVE-2025-2783
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
9.2%
95.1th percentile
CISA KEV
Listed
Added 2025-03-27 · patch by 2025-04-17
Weakness / dates
—
Published — · modified —
Timeline
- 2025-03-27 — Added to CISA KEV (actively exploited)
- 2025-04-17 — CISA patch-by deadline
Description
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.