Target Industry

To date this has targeted Russian media, educational institutions, and government agencies.

Overview

A critical zero-day vulnerability in Chrome, which allows bypassing its sandbox protection, has been discovered by Kaspersky researchers. Identified as CVE-2025-2783 the vulnerability has been exploited in Russian cyberespionage operations. The attacks were described by the researchers as technically sophisticated and indicative of an advanced persistent threat (APT) group. 

Impact

The attacks are part of a campaign named ‘Operation ForumTroll, which involves phishing emails that lead to infection upon clicking a link. The vulnerability can bypass Chrome’s sandbox protection and is used in conjunction with another exploit for remote code execution. This kind of vulnerability is particularly dangerous because it requires minimal user interaction to be exploited. It can lead to complete system compromise due to an error in logic between Chrome and the Windows OS.  

Affected Products

The affected version of Chrome of this vulnerability is134.0.6998.177/.178 for Windows 

Exploitation

The attack is initiated by phishing invitations leading to malicious websites. CVE-2025-2783 (CVSS score 9) affects Mojo, an inter-process communication (IPC) system used internally by the Google Chrome browser. It involves an incorrect handle provided in unspecified circumstances on Windows.  

Containment, Mitigations & Remediation

Google have released an urgent patch to address this high severity vulnerability in Chrome for Windows. Therefore, it is highly recommended to update to the latest version of Chrome. This includes users of Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi. In their advisory, Google has stated the patch will be available in the coming days/weeks, on the Google Chrome Releases webpage.  

Indicators of Compromise

The main indicator of compromise seems to be that victims are being redirected to a malicious URL called primakovreadings [.]info. 

Threat Landscape

Globally Chrome is the most popular web browser, and in Russia, it holds around 46% of the market share (Statcounter GlobalStats). Currently, the vulnerability is being actively exploited in the wild, targeting Russian organisations. With over five million organisations relying on Google products, the education and government sectors are at a higher risk of impact from this exploit.  

Although only Russia so far has been targeted, there is a high likelihood that this vulnerability could also be used to exploit Western organisations. This makes it particularly dangerous, as it requires minimal user interaction and can lead to complete system compromise.  

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing. 

Tactics, Techniques and Procedures

T1566.002: Phishing: Spearphishing Link 

T1497: Virtualization/Sandbox Evasion 

T1203: Exploitation for Client Execution 

Further Information

https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content