CVE-2025-2783: Google Chromium Mojo
EPSS9.2%No. 1301 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV75
Same product2
| Field | Value |
|---|---|
| Vendor | |
| Product | Chromium Mojo |
| Name | Google Chromium Mojo Sandbox Escape Vulnerability |
| Added to KEV | 2025-03-27 |
| US federal due date | 2025-04-17 |
| Ransomware use | Unknown |
| CWE | – |
CISA description
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2022-3075 | Google Chromium Mojo | 2022-09-08 | 5.8% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Google Chromium Mojo vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27.