SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Hook, Line, and Sinker: Chrome Patches Zero-Day Used in Phishing Attacks

Hook, Line, and Sinker: Chrome Patches Zero-Day Used in Phishing Attacks

In mid-March 2025, a deluge of personalized phishing emails took Russia by storm. When analyzed, the underlying vulnerability had researchers swimming in uncharted waters; they had found a new Chrome zero-day!

Mar 27, 2025By Meghana Raatni3 min read

In mid-March 2025, a deluge of personalized phishing emails took Russia by storm. When analyzed, the underlying vulnerability had researchers swimming in uncharted waters; they had found a new Chrome zero-day!

CVE-2025-2783 is a high-severity flaw that involves an incorrect handle provided in unspecified circumstances, potentially leading to a sandbox escape via a malicious file. The bug is present in Mojo, a collection of runtime libraries that facilitate Inter-Process Communication (IPC) across multiple platforms. Chromium browsers use Mojo to manage sandboxed processes for secure communication.

How does this exploit work?

As of March 27 2025, there isn’t much information available on the vulnerability itself. The Kaspersky researchers who discovered it have stated that they will only reveal technical details once most Chromium users have patched their browsers.

The exploit itself pertains to a phishing email that invites recipients to a scientific forum known as Primakov Readings. There are two links present within the email which claim to deliver program details and a registration form respectively. If an unsuspecting user takes the bait, they will be redirected to the attacker’s website, which will promptly infect their system with malware.

The campaign has been christened “Operation ForumTroll” by Kaspersky. The exploit is presently inactive, and the links redirect users to the official Primakov website, but Chromium users should still keep an eye out for any suspicious activity.

Products Affected

Google Chrome versions 134.0.6998.176 and below are vulnerable, and so are other Chromium-based browsers like Opera, Edge, Brave and Vivaldi.

Impact

Though the malefactors have not yet been reeled in, analysis of the malware and attack methodology suggests a high level of sophistication, hinting that a state-sponsored APT group might be pulling the strings. Operation ForumTroll primarily targeted Russian media outlets and educational institutions, presumably with espionage as the main goal.

Solution

Google wastes no time! Version 134.0.6998.177 is the patch for this flaw, so make sure to update all your browsers and stay away from any odd-looking links, since the threat actors can still reactivate the exploit mechanism.

Instantly Fix Risks with SanerNow Patch Management

SanerNow patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. SanerNow patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026