chromereleases.googleblog.com
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html GHSA-F87W-3J5W-V58P
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
Description
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) https://nvd.nist.gov/vuln/detail/CVE-2025-2783 https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html https://issues.chromium.org/issues/405143032
Description source: GitHub Advisory
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
CefSharp.OffScreenBrowse NuGet / CefSharp.OffScreen | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.OffScreen.NetCoreBrowse NuGet / CefSharp.OffScreen.NetCore | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.WinFormsBrowse NuGet / CefSharp.WinForms | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.WinForms.NetCoreBrowse NuGet / CefSharp.WinForms.NetCore | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.WpfBrowse NuGet / CefSharp.Wpf | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.Wpf.HwndHostBrowse NuGet / CefSharp.Wpf.HwndHost | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
CefSharp.Wpf.NetCoreBrowse NuGet / CefSharp.Wpf.NetCore | GitHub Advisory | Before 134.3.90 · Fixed in 134.3.90 | affected |
References
6github.com
https://github.com/cefsharp/CefSharp github.com
https://github.com/cefsharp/CefSharp/releases/tag/v134.3.90 github.com
https://github.com/cefsharp/CefSharp/security/advisories/GHSA-f87w-3j5w-v58p issues.chromium.org
https://issues.chromium.org/issues/405143032 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2783