Technology giant Google has just released an urgent security update for its Chrome browser, to fix the first serious zero-day vulnerability discovered in 2025.
Hacker groups have exploited the vulnerability, identified as CVE-2'25-2783, in attacks.
Zero-day vulnerability is a term used to describe security vulnerabilities that have not been disclosed or fixed yet. Hackers and cybercriminals will take advantage of these vulnerabilities to infiltrate the computer systems of businesses and corporations to steal or change data.
Google has issued a security alert describing the vulnerability as being of relatively high severity. The vulnerability allows attackers to bypass Chrome's sandbox protections, a key step in installing malware and taking control of a victim's computer.
A patch for the CVE-2'25-2783 vulnerability has been integrated by Google in Chrome version 134.0.6998.178. Google is currently limiting the release of technical details about the vulnerability to give users time to update and avoid being exploited by hackers.
Two security researchers Boris Larin and Igor Kuznetsov from the company that produces and distributes security software Kaspersky discovered and reported this vulnerability. According to Kaspersky, this vulnerability is an important link in a targeted attack campaign called 'Operation ForumTroll'.
The campaign uses sophisticated phishing emails, pretending to be invitations from the organizers of the scientific and expert forum 'Primakov Readings'. The emails target media outlets, educational institutions and government agencies in Russia. When recipients click on the malicious link in the email, they are redirected to a dangerous website where malware is deployed.
Kaspersky believes that the actors behind Operation ForumTroll also used another vulnerability to execute code remotely, but patching the Chrome vulnerability CVE-2'25-2783 was enough to break the entire infection chain.
According to Google, with the vulnerability being actively exploited, Google Chrome users, especially on Windows operating systems, are advised to urgently check and update their browser to version 134.0.6998.178 or newer./.
Source: https://www.vietnamplus.vn/google-phat-hanh-ban-cap-nhat-bao-mat-khan-cap-cho-trinh-duyet-chrome-post1023435.vnp
Comment (0)