CVE-2025-2783: Incorrect handle provided in unspecified circumstances in Mojo on Windows
Chromium: CVE-2025-2783 Incorrect handle provided in unspecified circumstances in Mojo on Windows
Other sources
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 134.0.6998.177
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2783?
CVE-2025-2783 has been classified as a high severity vulnerability due to its potential for exploitation.
How do I fix CVE-2025-2783?
To fix CVE-2025-2783, update Google Chrome to version 134.0.6998.177 or ensure that your Microsoft Edge (Chromium-based) is up-to-date.
Which versions of Chrome are affected by CVE-2025-2783?
CVE-2025-2783 affects Google Chrome versions prior to 134.0.6998.177.
Can Microsoft Edge users be affected by CVE-2025-2783?
Yes, users of Microsoft Edge (Chromium-based) are also susceptible to CVE-2025-2783 if they are using outdated versions.
Is there any workaround for CVE-2025-2783?
There are no known workarounds for CVE-2025-2783; it is recommended to update your browser to mitigate the vulnerability.