A newly discovered zero-day vulnerability in Google Chrome is raising serious concerns about user privacy and cybersecurity. The flaw, tracked as CVE-2025-2783, was actively exploited in the wild and enabled attackers to bypass the browser’s sandbox protections—potentially exposing browsing activity, login sessions, and sensitive data. Google has since released a fix in version 134.0.6998.178, urging users to update immediately.
Operation ForumTroll and targeted espionage
The flaw was uncovered by Kaspersky researchers Boris Larin and Igor Kuznetsov, who noticed a sharp rise in infections linked to a previously unknown malware strain. Their investigation revealed that threat actors were using this Chrome vulnerability as part of a larger espionage campaign, dubbed Operation ForumTroll, targeting entities primarily in Russia.
The attackers distributed phishing emails disguised as invitations to a scientific event, luring recipients into visiting a malicious website. Once compromised, victims’ systems were vulnerable to remote code execution, giving attackers deep access to data and communications.
How to protect yourself now
To stay protected, users should first ensure their Chrome browser is updated to version 134.0.6998.178 or later. This patch closes the security hole and disrupts the infection chain used in the attack. Users are also advised to avoid clicking on suspicious links or downloading attachments from unknown sources.
As the malware used in ForumTroll was sophisticated and aimed at monitoring online behavior and extracting private information, maintaining updated antivirus software and practicing good digital hygiene is critical. For organizations, additional monitoring for unusual network activity is recommended.
While Google has not revealed the full scope of affected users, this case highlights the real-world consequences of delayed software updates in a time of rising cyber-espionage threats.