Google pushed out an emergency patch for Chrome on Windows this week to stop attackers exploiting a sandbox-breaking zero-day vulnerability, seemingly used by snoops to target certain folks in Russia. Now Mozilla's doing damage control, too, after spotting a similar flaw – albeit unexploited, as far as we're aware – lurking in the code of its Firefox browser. The Chrome patch addresses a fairly vague vulnerability identified by Kaspersky, which it found after spotting a phishing campaign targeting Russian journalists, academics, and government agencies with bogus invites to an event. Victims who clicked the malicious link in an email didn't need to do anything else - the exploit immediately punched through Chrome's security sandbox, which among other things keeps webpage tabs and plugins isolated from each other, potentially leading to further exploitation that hasn't yet been documented publicly. "The vulnerability CVE-2025-2783 really left us scratching our heads, as, without doing anything obviously malicious or forbidden, it allowed the attackers to bypass Google Chrome’s sandbox protection as if it didn’t even exist," wrote Kaspersky researchers Igor Kuznetsov and Boris Larin. The Kaspersky duo said they did not themselves observe subsequent malware infections, but believe the exploit “was designed to run in conjunction with an additional exploit that enables remote code execution.” Malware targeting Russians is unusual, but on Thursday security shop Silent Push reported...
After Chrome patches zero-day used to target Russians, Firefox splats similar bug
The Register
·Iain Thomson
·Published Mar 28, 2025
·Updated
Affected Software
8 affected components
Google Chrome
Mozilla Firefox
Microsoft Edge
Opera Opera
Brave Brave
Tor Project Tor Browser
Google Chrome
Mozilla Firefox
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a recent zero-day vulnerability affecting Google Chrome and Mozilla Firefox that was used in targeted attacks against individuals in Russia.
2
What security implications are discussed in the article?
The article highlights the potential risks of sandbox-breaking vulnerabilities that can be exploited by attackers to bypass security measures.
3
What products or software are affected by the vulnerability?
The vulnerabilities primarily affect Google Chrome and Mozilla Firefox browsers.
4
What action did Google take in response to the vulnerability?
Google released an emergency patch for Chrome to fix the zero-day vulnerability and mitigate the risks.
5
Are there any indications of who is targeting victims with this vulnerability?
The article notes that the zero-day vulnerability was seemingly used by attackers to target specific individuals in Russia.