<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Chrome Zero-Day Exploited by Commercial Spyware in Nation-State Attacks

Chrome zero-day CVE-2025-2783 exploited by commercial spyware "Dante" in Operation ForumTroll targeting Russian and Belarus entities.
Content Team

Kaspersky researchers discovered that a Chrome zero-day vulnerability (CVE-2025-2783) was exploited earlier this year using commercial spyware called "Dante" from Memento Labs. The attacks, part of "Operation ForumTroll," targeted government and private entities in Russia and Belarus through personalized phishing emails.

Memento Labs is the successor to Hacking Team, which was compromised in 2015 but relaunched in 2019. The sophisticated exploit bypassed Chrome's sandbox protections by exploiting an obscure Windows quirk involving "pseudo handles" - a decades-old optimization that became a security vulnerability.

This case highlights how commercial spyware vendors are driving zero-day attacks against major tech companies. Google has patched the flaw, but researchers warn similar vulnerabilities may exist in other applications.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo