Get the latest tech news

Google Patches Chrome Sandbox Escape Zero-Day Caught By Kaspersky


wiredmikey shares a report from SecurityWeek: Google late Tuesday rushed out a patch for a sandbox escape vulnerability in its flagship Chrome browser after researchers at Kaspersky caught a professional hacking operation launching drive-by download exploits. The vulnerability, tracked as CVE-2025-2...

wiredmikey shares a report from SecurityWeek: Google late Tuesday rushed out a patch for a sandbox escape vulnerability in its flagship Chrome browser after researchers at Kaspersky caught a professional hacking operation launching drive-by download exploits. The vulnerability, tracked as CVE-2025-2783, was chained with a second exploit for remote code execution in what appears to be a nation-state sponsored cyberespionage campaign [dubbed Operation ForumTroll] targeting organizations in Russia. Kaspersky said it detected a series of infections triggered by phishing emails in the middle of March and traced the incidents to a zero-day that fired when victims simply clicked on a booby-trapped website from a Chrome browser.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Google

Google

Photo of Day

Day

Photo of Kaspersky

Kaspersky

Related news:

News photo

Google fixes Chrome zero-day exploited in espionage campaign

News photo

Mike Waltz takes ‘full responsibility’ for leaked Signal chat about Yemen strike | Defense Secretary accused reporter who received chats of ‘peddling hoaxes’ earlier in day

News photo

Google releases ‘most intelligent model to date,’ Gemini 2.5 Pro