Kaspersky discovers critical vulnerability in Google Chrome

A critical vulnerability in Google Chrome was discovered by Kaspersky. The exploit affected media, governments, and universities in March 2025.
A critical vulnerability in Google Chrome was discovered by Kaspersky. The exploit affected media, governments, and universities in March 2025.

 

Kaspersky Detects a Critical Vulnerability
in Google Chrome that allowed attackers to bypass the browser’s protection. The Russian company’s GReAT research team identified the exploit and alerted Google, who implemented a security patch to address the issue.

The vulnerability, registered as CVE-2025-2783, allowed attackers to bypass the browser’s sandbox protection. Kaspersky’s Global Research and Analysis Team (GReAT) discovered that the exploit required no additional user action other than clicking on a malicious link.

After promptly notifying Google, a security patch was deployed on March 25, 2025.

Targeted Phishing Campaign.

In mid-March 2025, Kaspersky detected a wave of infections triggered by phishing links sent via email. By clicking these links, users compromised their systems without needing to take any further action.

Researchers confirmed that the exploit took advantage of an unknown vulnerability in the latest version of Google Chrome, prompting Kaspersky to alert Google. A security patch was quickly implemented.

Operation ForumTroll.

Kaspersky named this campaign “Operation ForumTroll” because the attackers were sending phishing emails to media outlets, educational institutions, and government entities in Russia.

The malicious links directed users to a legitimate forum, “Primakov Readings,” but only after the exploit had executed. These links were designed with a very short lifespan to evade detection.

Complex Chain Exploit.

The zero-day vulnerability found in Google Chrome was part of a chain of at least two exploits. The first, a still-unknown remote code execution (RCE) exploit, appeared to initiate the attack, while the second phase, discovered by Kaspersky, was the bypass of sandbox protection.

Analyses suggest that the operation was primarily aimed at espionage, possibly involving a Threat Actor from an Advanced Persistent Threat (APT) group.

Fabio Assolini, Director of Kaspersky’s Global Research and Analysis Team (GReAT) for Latin America, explained the details of the discovery:

”This vulnerability stands out among the dozens of zero-day exploits we have uncovered over the years. The exploit bypassed Chrome’s sandbox protection without performing obvious malicious actions, as if the security barrier simply didn’t exist. The technical sophistication shown here suggests that it was developed by highly skilled actors with significant resources. We strongly recommend that all users update Google Chrome and any Chromium-based browser to the latest version to protect themselves against this vulnerability.”

Recognition and Security Measures.

Google publicly recognized Kaspersky for discovering and reporting the vulnerability, highlighting their ongoing commitment to collaboration in the cybersecurity field.

The company continues to investigate Operation ForumTroll and plans to release a detailed report once user security is ensured. In the meantime, Kaspersky’s products already provide protection against the chain of exploits and associated malware.

Kaspersky Next EDR Expert, a key tool in the Kaspersky Next XDR (Extended Detection and Response) platform, played a crucial role in early detection of the attack. Thanks to the quick identification, the behavior of the vulnerability and its impact were thoroughly analyzed.

Recommendations for Users.

Kaspersky experts recommend the following measures to protect against similar attacks:

– Keep software updated: Regularly install patches, especially for browsers like Google Chrome.

– Implement layered security: Use solutions such as Kaspersky Next XDR Expert to automatically detect and respond to advanced threats.

– Leverage threat intelligence: Utilize services like Kaspersky Threat Intelligence to stay informed about emerging vulnerabilities and attacker tactics.

This finding follows the earlier identification of another zero-day in Chrome (CVE-2024-4947) by the GReAT team, which was exploited last year by the Lazarus APT group in a cryptocurrency theft campaign.

Share:
Hosting Web
Most Read