After Chrome patches zero-day used to target Russians, Firefox splats similar bug
ID: 44f8a4f3-5d10-534c-aa0b-925401edad2c
STIX ID: report--44f8a4f3-5d10-534c-aa0b-925401edad2c
Feed Name: The Register (Security)
Google released an emergency Windows patch for a sandbox-breaking zero-day (CVE-2025-2783) that Kaspersky observed being used in a phishing campaign targeting Russian journalists, academics, and government agencies; Mozilla subsequently patched a similar IPC-related sandbox escape (CVE-2025-2857) in Firefox and the Tor Browser issued an urgent Windows release. The flaws allow handle leaks and sandbox escapes that could be combined with a remote code execution exploit, posing a high-risk threat to users of Chromium-based and Firefox-derived browsers until patches are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
