Dante Exploited in Chrome Zero-Day Attack

28 Oct 2025

Researchers discovered Dante, a commercial spyware, used in a Chrome zero-day attack targeting Russian media and government organizations in March 2025.

Vulnerability Details

The zero-day, rated 8.3/10, involved an "incorrect handle" vulnerability in Google Chrome. The flaw allowed attackers to escape the browser's sandbox and exfiltrate sensitive files from victims' systems.

  • Attack vector: Exploited incorrect handle vulnerability.
  • Date observed: March 2025.
  • Targets: Russian media, government, educational, and financial sectors.
  • Attribution: Allegedly developed by Memento Labs.
  • Tools: Malicious file for sandbox escape.

Memento Labs and Its History

Dante, reportedly developed by Memento Labs, a company linked to the now-defunct Hacking Team, has been sold as a counterterrorism tool. Investigators noted its potential misuse against political opponents, journalists, and activists.

Memento Labs, formed from assets of InTheCyberGroup in 2019, showcased Dante at ISS World Middle East and Africa in 2023.

Risks Highlighted

Kaspersky Lab's report highlights the severe risk of combining browser zero-day vulnerabilities with commercial spyware, emphasizing the potential for high-profile digital espionage.

Google Chrome

Google Chrome download for free to PC or mobile

Latest update Google Chrome download for free for Windows PC or Android mobile

3
713 reviews
6890 downloads

News and reviews about Google Chrome

28 Oct 2025

Dante Exploited in Chrome Zero-Day Attack

Dante, a spyware, exploited a Chrome zero-day targeting Russian entities in March 2025.

Read more

20 Sep 2025

Gemini Enhancements Transform Chrome with Subtle AI Tools

Gemini introduces refined AI features to Chrome, enhancing browser functionality. Focused on practical tasks, Gemini's tools aid navigation, assist task execution, and improve search efficiency. Initial rollout is limited, highlighting Google's commitment to user privacy and control.

Read more

03 Sep 2025

Chrome Gains Market Share Despite Microsoft's Push for Edge

In a surprising turn, Google Chrome's market share has surged as Microsoft's campaign urging Windows users to switch to Edge appears to have backfired.

Read more

13 May 2025

Gemini Enhances Google's Anti-Scam Measures Across Platforms

Gemini's AI algorithms enhance Google's detection of online scams on Chrome, Search, and Android, significantly reducing fraudulent activity.

Read more

11 Mar 2025

Installing Google Chrome on Windows 11: A Quick Guide

Learn how to download, install, and set Google Chrome as the default browser on Windows 11 with these simple steps.

Read more

05 Mar 2025

Google Enhances Password Manager with New Bulk Deletion Feature

Google is reportedly updating Password Manager to include a delete all option, simplifying the removal of saved credentials.

Read more

03 Mar 2025

Google Enhances Chrome with Android Malware Protection

Google introduces a new malware detector in Chrome for APK files, providing additional security for Android apps not from the Play Store.

Read more

04 Aug 2024

Google Releases Critical Chrome Security Update Addressing Key Vulnerability

Google has released a critical security update for Chrome, version 127.0.6533.88/89, addressing CVE-2024-6990, a memory vulnerability in the browser’s web graphics rendering engine. The update also includes two high-severity fixes. Users are advised to update and restart Chrome.

Read more

01 Aug 2024

Google Chrome Enhances Security with App-Bound Encryption in Version 127

Google Chrome version 127 for Windows now features app-bound encryption to enhance cookie protection and defend against malware. This update ties encrypted data to the app's identity, preventing unauthorized access. The new mechanism also safeguards passwords, payment data, and authentication tokens.

Read more

29 Jul 2024

Chrome Password Manager Bug Affects 15 Million Users, Issue Resolved

A bug in Chrome's password manager led to the loss of over 15 million passwords on July 24-25, affecting a quarter of users. The issue was specific to Chrome M127 on Windows. Google provided a temporary fix and has since resolved the glitch. Email verification issues for new Workspace accounts were also reported.

Read more