Target Industry
To date this has targeted Russian media, educational institutions, and government agencies.
Overview
A critical zero-day vulnerability in Chrome, which allows bypassing its sandbox protection, has been discovered by Kaspersky researchers. Identified as CVE-2025-2783 the vulnerability has been exploited in Russian cyberespionage operations. The attacks were described by the researchers as technically sophisticated and indicative of an advanced persistent threat (APT) group.
Impact
The attacks are part of a campaign named ‘Operation ForumTroll, which involves phishing emails that lead to infection upon clicking a link. The vulnerability can bypass Chrome’s sandbox protection and is used in conjunction with another exploit for remote code execution. This kind of vulnerability is particularly dangerous because it requires minimal user interaction to be exploited. It can lead to complete system compromise due to an error in logic between Chrome and the Windows OS.
Affected Products
The affected version of Chrome of this vulnerability is 134.0.6998.177/.178 for Windows
Exploitation
The attack is initiated by phishing invitations leading to malicious websites. CVE-2025-2783 (CVSS score 9) affects Mojo, an inter-process communication (IPC) system used internally by the Google Chrome browser. It involves an incorrect handle provided in unspecified circumstances on Windows.
Containment, Mitigations & Remediation
Google have released an urgent patch to address this high severity vulnerability in Chrome for Windows. Therefore, it is highly recommended to update to the latest version of Chrome. This includes users of Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi. In their advisory, Google has stated the patch will be available in the coming days/weeks, on the Google Chrome Releases webpage.
Indicators of Compromise
The main indicator of compromise seems to be that victims are being redirected to a malicious URL called ‘primakovreadings [.]info’.
Threat Landscape
Globally Chrome is the most popular web browser, and in Russia, it holds around 46% of the market share (Statcounter GlobalStats). Currently, the vulnerability is being actively exploited in the wild, targeting Russian organisations. With over five million organisations relying on Google products, the education and government sectors are at a higher risk of impact from this exploit.
Although only Russia so far has been targeted, there is a high likelihood that this vulnerability could also be used to exploit Western organisations. This makes it particularly dangerous, as it requires minimal user interaction and can lead to complete system compromise.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Tactics, Techniques and Procedures
T1566.002: Phishing: Spearphishing Link
T1497: Virtualization/Sandbox Evasion
T1203: Exploitation for Client Execution
Further Information
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html













