Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
https://www.securityweek.com/chrome-sandbox-escape-earns-researcher-250000/
https://www.securityweek.com/chrome-136-update-patches-vulnerability-with-exploit-in-the-wild/
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html
https://issues.chromium.org/issues/412578726
Source: Mitre, NVD
Published: 2025-08-22
Updated: 2025-08-25
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.6
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS: 0.00136