{"cveID":"CVE-2025-2783","vendorProject":"Google","product":"Chromium Mojo","vulnerabilityName":"Google Chromium Mojo Sandbox Escape Vulnerability","dateAdded":"2025-03-27","shortDescription":"Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-04-17","knownRansomwareCampaignUse":"Unknown","notes":"https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-2783","cwes":[],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-2783","technique":"T1203","technique_name_at_mapping":"Exploitation for Client Execution","mapping_type":"exploitation_technique","capability_group":"sandbox_bypass","comments":"This vulnerability allows attackers to escape Chrome’s sandbox through a Mojo IPC message crafted to trigger higher privilege. Exploitation has been reported as part of a cyber-espionage campaign.","references":["https://fidelissecurity.com/vulnerabilities/cve-2025-2783/ https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-2783","technique":"T1497","technique_name_at_mapping":"Virtualization/Sandbox Evasion","mapping_type":"secondary_impact","capability_group":"sandbox_bypass","comments":"This vulnerability allows attackers to escape Chrome’s sandbox through a Mojo IPC message crafted to trigger higher privilege. Exploitation has been reported as part of a cyber-espionage campaign.","references":["https://fidelissecurity.com/vulnerabilities/cve-2025-2783/ https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-2783","technique":"T1548","technique_name_at_mapping":"Abuse Elevation Control Mechanism","mapping_type":"primary_impact","capability_group":"sandbox_bypass","comments":"This vulnerability allows attackers to escape Chrome’s sandbox through a Mojo IPC message crafted to trigger higher privilege. Exploitation has been reported as part of a cyber-espionage campaign.","references":["https://fidelissecurity.com/vulnerabilities/cve-2025-2783/ https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1203","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Client Execution","name_at_mapping":"Exploitation for Client Execution","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":35,"has_detection_strategy":true},{"id":"T1497","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Virtualization/Sandbox Evasion","name_at_mapping":"Virtualization/Sandbox Evasion","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true},{"id":"T1548","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Abuse Elevation Control Mechanism","name_at_mapping":"Abuse Elevation Control Mechanism","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":24,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}