Microsoft published security advisories for two Chromium vulnerabilities affecting its browser platform, including CVE-2025-2783, an incorrect handle issue in Mojo on Windows, and CVE-2025-13637, an inappropriate implementation flaw in Downloads. The advisories indicate the issues were tracked through Microsoft's Security Update Guide as Chromium-related weaknesses requiring browser security updates.
The flaws affect separate browser components and could expose Windows users to security risk if left unpatched, with one issue tied specifically to inter-process communication through Mojo and the other to download handling logic. Microsoft did not provide detailed public synopses in the notices, but the entries show the company issued coordinated guidance to ensure Chromium-based deployments receive the relevant fixes.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2025-13637 to its Security Update Guide, describing a Chromium vulnerability related to inappropriate implementation in Downloads.
Microsoft added CVE-2025-2783 to its Security Update Guide, describing a Chromium vulnerability involving an incorrect handle in Mojo on Windows.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.