Google Issues Emergency Patch for Actively Exploited Chrome Vulnerability
“The difference between a good day and a security incident is often just one unpatched vulnerability.” – Unknown
A Wake-Up Call for Chrome Users
A critical security flaw in Chrome has been discovered—and it’s already being exploited. In response, Google has issued an urgent out-of-band patch to fix the issue. The vulnerability, tracked as CVE-2025-2783, is no small matter. It’s being used in live attacks targeting high-profile organisations, particularly in Russia.
This isn’t just another routine update. It’s a full-blown red alert. If you’re using Chrome, this affects you directly. And if you’re managing devices at scale, the time to act is now.
Let’s break down what’s happening and what you should do next.
What Is CVE-2025-2783?
CVE-2025-2783 is a high-severity vulnerability in Chrome for Windows. The flaw is linked to how Chrome’s Mojo component—responsible for inter-process communication—handles certain system calls. In simple terms, the issue lies in how Chrome interacts with the Windows operating system, allowing attackers to bypass important security barriers.
The Scope of the Threat
Security researchers at Kaspersky discovered that this flaw is already being used in targeted attacks. The campaign, dubbed Operation ForumTroll, used phishing emails to trick victims into clicking malicious links. The moment a target opened the link in Chrome—bam!—the device was compromised. No extra clicks. No downloads. No second chances.
It’s technically sophisticated and almost certainly the work of a state-sponsored advanced persistent threat (APT).
Who’s Affected?
This isn’t just about one country or one group of users. While the current exploitation targets organisations in Russia—including media outlets, universities, and government institutions—the vulnerability exists in all Windows installations of Chrome.
If you’re running Chrome version prior to 134.0.6998.177/.178 on Windows, you’re vulnerable.
Don’t Use Chrome on Windows? You’re Still at Risk
Other Chromium-based browsers—like Microsoft Edge, Brave, Opera, and Vivaldi—share the same underlying code. These browsers are likely vulnerable too, although patches may still be in progress. If you’re using any of these, keep a sharp eye out for updates.
What Should You Do Right Now?
✅ Step 1: Update Chrome Immediately
Open Chrome, go to:
Settings > About Chrome
If an update is available, it will automatically begin downloading. Restart the browser to apply the patch.
Your goal is to get to:
Chrome version 134.0.6998.177 or 134.0.6998.178 on Windows.
🔄 Step 2: Monitor Other Chromium-Based Browsers
If your organisation uses browsers like Edge or Brave, make sure IT teams are monitoring for relevant patches. Push updates organisation-wide as soon as they become available.
🧠 Step 3: Educate and Alert Teams
Remind your teams about phishing email risks. In the reported attacks, users were lured in with what appeared to be invitations to a credible forum—Primakov Readings. One click was all it took.
Provide clear guidance: Don’t click unknown links, even if they look legitimate.
Final Thoughts: This Isn’t the Last Zero-Day
This is the first actively exploited Chrome zero-day of 2025. But it won’t be the last. Threat actors are becoming smarter. Attacks are more targeted. And users are still the weakest link.
But we have tools. We have updates. And we have the power to respond quickly. Patch fast. Educate often. Stay secure.