Tech and AIGoogle fixes Chrome zero-day security flaw used in hacking...

Google fixes Chrome zero-day security flaw used in hacking campaign targeting journalists

-


Google said it has fixed a vulnerability in its Chrome browser for Windows that malicious hackers have used to break into victims’ computers.

In a brief note on Tuesday, Google said that it fixed the vulnerability, tracked as CVE-2025-2783, that was discovered by researchers at security firm Kaspersky earlier this month. 

Google said it was aware of reports that an exploit for the bug “exists in the wild.” The bug is referred to as a zero-day because the vendor — in this case, Google — was given no time to fix the bug before it was exploited.

According to Kaspersky, the bug was exploited as part of a hacking campaign targeting Windows computers running Chrome. 

In a blog post, Kaspersky called the campaign “Operation ForumTroll,” and said victims were targeted with a phishing email inviting them to a Russian global political summit. When a link in the email was clicked, victims were taken to a malicious website that immediately exploits the bug to gain access to the victim’s PC data. 

Kaspersky provided little detail about the bug at the time of the Chrome patch, but said that the bug allowed the attackers to bypass Chrome’s sandbox protections, which limit the browser’s access to other data on the user’s computer. Kaspersky said the bug affects all other browsers based on Google’s Chromium engine.

In a separate analysis, Kaspersky said the bug was likely used in an espionage campaign, typically designed to stealthily monitor and steal data from a target’s device, usually over a period of time. The Russia-headquartered security firm said the hackers sent personalized phishing emails to Russian media representatives and employees at educational institutions. 

It’s unclear who was exploiting the bug, but Kaspersky attributed the campaign to a likely state-sponsored or government-backed group of hackers. 

Browsers like Chrome are a frequent target for malicious hackers and government-backed groups. Zero-day bugs capable of breaking through their protections and into the victim’s sensitive device data can be sold at high prices. In 2024, one zero-day broker was offering up to $3 million for exploitable bugs that can be triggered from over the internet. 

Google said Chrome updates will roll out over the coming days and weeks.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

60 Russian Crypto Firms Sanctioned by Ukraine for Evading Restrictions

Ukraine has imposed sanctions on 60 crypto firms in Russia, including officials in the Central Bank of Russia....

Crypto influencer Tiffany Fong rejected Elon Musk’s baby-making offer, report

Elon Musk slid into the DMs of cryptocurrency influencer Tiffany Fong and asked her to have his baby,...

The 8 Best Travel Pillows (2025), Tested on Planes

Cabeau’s Evolution Earth neck pillow is covered in RPET, a super-soft, washable fabric made with recycled plastic bottles....

Chinese Regulators Raise Alarm on Illicit Stablecoin Activity

Officials from Shenzhen have issued cautionary advice to the public, recommending that they pay maximum attention when operating...

Advertisement

Abandoned DeFi websites used to host crypto wallet drainers

The DeFi website scam relies on former users of now-defunct projects coming back to remove previously deposited funds. Source...

ChatGPT is testing a mysterious new feature called ‘study together’

Some ChatGPT subscribers are reporting a new feature appearing in their drop-down list of available tools called “Study...

Must read

60 Russian Crypto Firms Sanctioned by Ukraine for Evading Restrictions

Ukraine has imposed sanctions on 60 crypto firms...

Crypto influencer Tiffany Fong rejected Elon Musk’s baby-making offer, report

Elon Musk slid into the DMs of cryptocurrency...

You might also likeRELATED
Recommended to you