This vulnerability is known to have been exploited in attacks. Update affected browsers immediately.
CVE details
CVE-2025-2783
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.
Description
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
Affected products
- Google Chrome · → 134.0.6998.177
- Chromium · → 134.0.6998.177
Overlaps: Google Chrome, Chromium