Input validation error in Google Chromium - CVE-2025-2783

 

Input validation error in Google Chromium - CVE-2025-2783

Published: March 25, 2025 / Updated: April 1, 2026


Vulnerability identifier: #VU106029
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2783
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input, related to Mojo on Windows. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Prisma Access Browser

How to mitigate CVE-2025-2783

Install update from vendor's website.

Google Chromium - update to 134.0.6998.178
Microsoft Edge - update to 134.0.3124.93
Google Chrome - update to 134.0.6998.177
Prisma Access Browser - update to 134.29.5.178

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins