Exploitation Summary
CVE-2025-2783 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 27, 2025. EIP tracks 8 public exploits from researchers including nu11secur1ty, Alchemist3dot14, Leviticus-Triage.
AI-analyzed exploit summary This is a proof-of-concept (PoC) for CVE-2025-2783, demonstrating a sandbox escape and privilege escalation vulnerability in Microsoft Edge's Mojo IPC subsystem. The exploit simulates malicious IPC communication to escape sandbox restrictions and escalate privileges.
Description
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
Exploits (8)
This is a proof-of-concept (PoC) for CVE-2025-2783, demonstrating a sandbox escape and privilege escalation vulnerability in Microsoft Edge's Mojo IPC subsystem. The exploit simulates malicious IPC communication to escape sandbox restrictions and escalate privileges.
This is a simulated PoC for CVE-2025-2783, demonstrating a sandbox escape vulnerability in Chrome's Mojo IPC framework. It includes phishing delivery, memory fuzzing, and IPC simulation for educational purposes.
The repository appears to be a framework for Chrome exploits but lacks actual exploit code for CVE-2025-2783. It contains extensive documentation, contribution guidelines, and placeholder structures but no functional PoC or technical details specific to the CVE.
This repository contains a proof-of-concept for CVE-2025-2783, demonstrating a sandbox escape vulnerability in Google Chrome (version 134.0.6998.177) via improper handle validation in the Mojo IPC system. The code simulates the creation of a Mojo message pipe, injection of a fake handle, and attempts to read restricted system files to illustrate a sandbox breakout.
This repository provides a detailed technical analysis and conceptual demonstration of CVE-2025-2783, a Chrome Mojo IPC handle confusion vulnerability leading to sandbox escape on Windows. The code simulates the crafted Mojo IPC messages but does not contain a functional exploit against patched versions.
This repository contains a functional exploit PoC for CVE-2025-2783, leveraging the MinHook library for API hooking on x64/x86 architectures. The exploit includes shellcode execution capabilities and demonstrates memory manipulation techniques.
This repository contains a functional exploit for CVE-2025-2783, leveraging the MinHook library to perform API hooking and memory manipulation for privilege escalation or code execution. The PoC includes shellcode and demonstrates a hooking-based attack on a Windows target.
This repository contains a full-chain exploit for CVE-2025-2783, targeting Chromium's Ipcz communication layer to achieve sandbox escape and arbitrary code execution. The exploit leverages a V8 Type Confusion vulnerability and thread hijacking to execute shellcode in a high-privileged context.
References (3)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H