Published On: Mar 28, 2025 16:52
Advisory No: TZCERT-SA-25-0079
Source: Chrome
Software Affected: Google Chrome for Windows versions prior to 134.0.6998.177/.178
A critical security vulnerability has been discovered in Google Chrome for Windows. This flaw has been actively exploited in the wild, allowing attackers to execute arbitrary code on affected systems. Google has released an emergency patch to address this issue.
The vulnerability tracked as CVE-2025-2783 with a CVSS score of 8.3 (High) exists due to improper handling of Inter-Process Communication (IPC) within Mojo, a key Chromium component. The flaw is actively exploited via malicious websites, phishing campaigns, and drive-by downloads, allowing attackers to bypass Chrome’s sandbox and execute arbitrary code.
Successful exploitation of this vulnerability could allow attackers to execute arbitrary code, gain unauthorized access to sensitive data, install malware, and potentially take full control of affected systems. This poses a significant risk to users and organizations, especially given that the vulnerability is actively being exploited in targeted attacks.
To mitigate the risk posed by this vulnerability, Users and Administrators are encouraged to apply updates to the latest Google Chrome version. Automatic updates should be enabled to ensure timely patches.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.