logo

After Chrome patches zero-day used to target Russians, Firefox splats similar bug

ID: 44f8a4f3-5d10-534c-aa0b-925401edad2c

STIX ID: report--44f8a4f3-5d10-534c-aa0b-925401edad2c

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-28

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Google released an emergency Windows patch for a sandbox-breaking zero-day (CVE-2025-2783) that Kaspersky observed being used in a phishing campaign targeting Russian journalists, academics, and government agencies; Mozilla subsequently patched a similar IPC-related sandbox escape (CVE-2025-2857) in Firefox and the Tor Browser issued an urgent Windows release. The flaws allow handle leaks and sandbox escapes that could be combined with a remote code execution exploit, posing a high-risk threat to users of Chromium-based and Firefox-derived browsers until patches are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.