Google has fixed a very serious zero-day vulnerability in its Chrome browser, which was allegedly used in espionage attacks against Russian organizations.

The vulnerability is tracked as CVE-2025-2783 and was discovered by Boris Larin and Igor Kuznetsov of Kaspersky. According to the researchers, exploiting it allows attackers to bypass the browser and deploy malware.
Google has patched a zero-day vulnerability in Chrome on the Stable Desktop channel, with the updated builds rolling out to all Windows users (134.0.6998.178). The company said that some people may see the security update after a few days or weeks.
See also: Microsoft fixes zero-day in Windows Kernel
Users who prefer not to update Chrome manually can set the browser to automatically check for new updates and install them at the next launch.
Google did not provide further details about the attacks that used the Chrome vulnerability. The company usually does this until the majority of users have applied the update to their systems.
However, Kaspersky researchers who discovered the zero-day vulnerability have published a report with additional details. As we said above, attackers are using exploits for CVE-2025-2783 to bypass Chrome's sandbox protections and infect targets with malware.
This vulnerability is being used in phishing attacks, redirecting victims to the domain primakovreadings[.]info. These attacks are part of a cyberespionage targeting Russian organizations.
See also: Apple patches third zero-day vulnerability this year
“ The malicious emails contained invitations purporting to come from the organizers of a scientific forum, “Primakov Readings.” They targeted media outlets, educational institutions , and government organizations in Russia. Based on the content of the emails, we named the campaign Operation ForumTroll ,” Kaspersky researchers said
While analyzing these attacks, Kaspersky researchers found that the attackers also used a second exploit that allowed remote code execution.
CVE-2025-2783 is the first zero-day vulnerability in Chrome that Google has patched this year. Last year, the company patched 10 zero-days.

What are the latest techniques for dealing with Zero-Day vulnerabilities?
One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.
Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.
See also: Edimax Camera Zero-Day Exploited by Botnets
Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.
Source: www.bleepingcomputer.com
