CVE-2025-14174
published 2025-12-12CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a…
PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-01-02
Exploited in the wild
EPSS
22.72%
97.5th percentile
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.3_and_ipados | — | — |
| apple | ios_26.2_and_ipados | — | — |
| apple | ios_26.3_and_ipados | — | — |
| apple | ios_and_ipados | < 26.3 | 26.3 |
| apple | ipados | < 18.7.3 | 18.7.3 |
| apple | ipados | < 26.3 | 26.3 |
| apple | ipados | >= 26.0 < 26.2 | 26.2 |
| apple | iphone_os | < 18.7.3 | 18.7.3 |
| apple | iphone_os | < 26.3 | 26.3 |
| apple | iphone_os | >= 26.0 < 26.2 | 26.2 |
| apple | macos | < 26.3 | 26.3 |
| apple | macos | < 26.2 | 26.2 |
| apple | macos | < 26.3 | 26.3 |
| apple | macos | >= 26.0 < 26.2 | 26.2 |
| apple | macos_tahoe | — | — |
| apple | macos_tahoe | — | — |
| apple | safari | < 26.2 | 26.2 |
| apple | safari | — | — |
| apple | tvos | < 26.3 | 26.3 |
| apple | tvos | < 26.2 | 26.2 |
| apple | tvos | < 26.3 | 26.3 |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | visionos | < 26.3 | 26.3 |
| apple | visionos | < 26.2 | 26.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-14174 is a use-after-free in WebKit (Apple) and an out-of-bounds memory access in ANGLE (Google Chrome on Mac); exploitation is triggered via processing maliciously crafted web content / a crafted HTML page delivered remotely. ↗
- →The vulnerability was exploited in the wild as part of a chained, extremely sophisticated targeted attack alongside CVE-2025-43529 and CVE-2026-20700; detections should correlate exploitation of these three CVEs together. ↗
- →Google's Threat Analysis Group (TAG) discovered the related CVE-2026-20700 exploit chain that includes CVE-2025-14174; TAG attribution suggests a nation-state or advanced threat actor targeting specific individuals. ↗
- →The Chrome-side vector is the ANGLE graphics library used for WebGL; monitor for anomalous WebGL/ANGLE renderer crashes or memory access violations in Chrome on macOS prior to version 143.0.7499.110. ↗
- →On the Apple side, the root cause is a use-after-free in WebKit; monitor for WebKit/Safari process crashes or unexpected memory write activity on unpatched iOS (<18.7.3 / <iOS 26), iPadOS, and macOS Tahoe devices. ↗
- ·CVE-2025-14174 maps to two distinct vulnerabilities in two separate products: an out-of-bounds memory access in ANGLE in Google Chrome on Mac (fixed in Chrome 143.0.7499.110), and a use-after-free in WebKit affecting Apple platforms (fixed in iOS 18.7.3, iPadOS 18.7.3, Safari 26.2, and macOS Tahoe 26.2). Detection rules must account for both codebases separately. ↗
- ·Exploitation has been confirmed in the wild (CISA KEV listed, Has Public Exploit: Yes per Wiz) and is described as part of 'extremely sophisticated' targeted attacks; patch prioritization should reflect active exploitation rather than CVSS score alone. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-14174: tvOS 26.3
vendor_apple·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: tvOS 26.3
Apple Security Update: About the security content of tvOS 26.3
Product: tvOS
Version: 26.3
CVE: CVE-2025-14174
Component: CoreServices
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with improved state handling.
Apple
CVE-2025-14174: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2025-14174
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2025-14174: visionOS 26.3
vendor_apple·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: visionOS 26.3
Apple Security Update: About the security content of visionOS 26.3
Product: visionOS
Version: 26.3
CVE: CVE-2025-14174
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2025-14174: watchOS 26.3
vendor_apple·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: watchOS 26.3
Apple Security Update: About the security content of watchOS 26.3
Product: watchOS
Version: 26.3
CVE: CVE-2025-14174
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2025-14174: iOS 26.3 and iPadOS 26.3
vendor_apple·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2025-14174
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Palo Alto
PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026)
vendor_paloalto·2026-01-14·CVSS 8.8
[HIGH] PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026)
PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_18.html https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_11.html https://chromereleases.google
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2026-01-13
CVE-2025-14174 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: webkitgtk: Use-after-free due to improper memory management
vendor_redhat·2025-12-16·CVSS 8.8
CVE-2025-43529 [HIGH] CWE-825 webkitgtk: webkitgtk: Use-after-free due to improper memory management
webkitgtk: webkitgtk: Use-after-free due to improper memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
A flaw was found in webkitgtk where when processing a maliciously crafted web content a use-after-free type of weaknesses may be triggered leading to a remote code execution in the client mac
Apple
CVE-2025-14174: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: Safari 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: Safari 26.2
Apple Security Update: About the security content of Safari 26.2
Product: Safari
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: visionOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: visionOS 26.2
Apple Security Update: About the security content of visionOS 26.2
Product: visionOS
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: watchOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: watchOS 26.2
Apple Security Update: About the security content of watchOS 26.2
Product: watchOS
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: visionOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: visionOS 26.2
Apple Security Update: About the security content of visionOS 26.2
Product: visionOS
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
CISA
Google Chromium Out of Bounds Memory Access Vulnerability
cisa·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] Google Chromium Out of Bounds Memory Access Vulnerability
Vulnerability: Google Chromium Out of Bounds Memory Access Vulnerability
Affected: Google Chromium
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html ; https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security ; https://nv
Apple
CVE-2025-43529: Safari 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: Safari 26.2
Apple Security Update: About the security content of Safari 26.2
Product: Safari
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-43529: tvOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: tvOS 26.2
Apple Security Update: About the security content of tvOS 26.2
Product: tvOS
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: tvOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: tvOS 26.2
Apple Security Update: About the security content of tvOS 26.2
Product: tvOS
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2025-14174: watchOS 26.2
vendor_apple·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: watchOS 26.2
Apple Security Update: About the security content of watchOS 26.2
Product: watchOS
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Description: A use-after-free issue was addressed with improved memory management.
Red Hat
Google Chrome: chromium: webkitgtk: Out of bounds memory access via crafted HTML page
vendor_redhat·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CWE-823 Google Chrome: chromium: webkitgtk: Out of bounds memory access via crafted HTML page
Google Chrome: chromium: webkitgtk: Out of bounds memory access via crafted HTML page
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
A flaw was found in ANGLE in Google Chrome. This vulnerability allows a remote attacker to perform out of bounds memory access via a crafted HTML (HyperText Markup Language) page. Although this was reported on Google Chrome, this issue also affected the WebKitGTK package with the same possible outcome.
Statement: This vulnerability is rated as Important by the Red Hat Product Security. A maliciously crafted web page may lead to out of bound memory access, specially in WebKitGTK component, and may
Chrome
Stable Channel Update for Desktop: CVE-2025-14174
vendor_chrome·2025-12-10·CVSS 8.8
CVE-2025-14174 [HIGH] Stable Channel Update for Desktop: CVE-2025-14174
Stable Channel Update for Desktop
CVE-2025-14174: Out of bounds memory access in ANGLE. Reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on 2025-12-05 [$2000][ 460599518 ] Medium CVE-2025-14372: Use after free in Password Manager
Reported by Weipeng Jiang (@Krace) of VRI on 2025-11-14 [$2000][ 461532432 ] Medium CVE-2025-14373: Inappropriate implementation in Toolbar
Severity: high
Microsoft
Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE
vendor_msrc·2025-12-09·CVSS 8.8
CVE-2025-14174 [HIGH] Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE
Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2025-14174 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand sid
Debian
CVE-2025-43529: webkit2gtk - A use-after-free issue was addressed with improved memory management. This issue...
vendor_debian·2025·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: webkit2gtk - A use-after-free issue was addressed with improved memory management. This issue...
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Scope: local
bookworm: resolved (fixed in 2.50.4-1~deb12u1)
bullseye: resolved (fixed in 2.50.4-1~deb11u1)
forky: resolved (fixed in 2.50.4-1)
sid: resolved (fixed in 2.50.4-1)
trixie: resolved (fixed in 2.50.4-1~deb13u1)
Debian
CVE-2025-14174: chromium - Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499...
vendor_debian·2025·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: chromium - Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499...
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-j5x8-2r52-c3ff: A memory corruption issue was addressed with improved state management
ghsa_unreviewed·2026-02-12·CVSS 8.8
CVE-2026-20700 [HIGH] CWE-119 GHSA-j5x8-2r52-c3ff: A memory corruption issue was addressed with improved state management
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
GHSA
GHSA-m9mp-fmfc-g6gc: A use-after-free issue was addressed with improved memory management
ghsa_unreviewed·2025-12-17·CVSS 8.8
CVE-2025-43529 [HIGH] CWE-416 GHSA-m9mp-fmfc-g6gc: A use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
OSV
CVE-2025-43529: A use-after-free issue was addressed with improved memory management
osv·2025-12-17·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: A use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
OSV
CVE-2025-43529: A use-after-free issue was addressed with improved memory management
osv·2025-12-17·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529: A use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
OSV
CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143
osv·2025-12-12·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
GHSA
GHSA-9fjm-6w64-76r7: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143
ghsa_unreviewed·2025-12-12
CVE-2025-14174 [HIGH] CWE-119 GHSA-9fjm-6w64-76r7: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium Out of Bounds Memory Access Vulnerability
vulncheck·2025·CVSS 8.8
CVE-2025-14174 [HIGH] Google Chromium Out of Bounds Memory Access Vulnerability
Google Chromium Out of Bounds Memory Access Vulnerability
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edi
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
blogs_bleepingcomputer·2026-04-01·CVSS 8.8
CVE-2025-31277 [HIGH] Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Lawrence Abrams
In March, researchers at Lookout, iVerify, and Google Threat Intelligence revealed a new "DarkSword" exploit kit that targeted iPhones running iOS 18.4 through 18.7.
The six vulnerabilities used by the DarkSword exploit kit are tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
While iOS exploits have typically been used in highly targeted spyware campaigns, this iOS exploit kit was used much more widely, including by Turkish commercial surveillance vendor PARS Defense, a threat actor tracked as UNC6748, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-stealing mal
Bleepingcomputer
New DarkSword iOS exploit used in infostealer attack on iPhones
blogs_bleepingcomputer·2026-03-18·CVSS 8.8
CVE-2025-31277 [HIGH] New DarkSword iOS exploit used in infostealer attack on iPhones
## New DarkSword iOS exploit used in infostealer attack on iPhones
## Bill Toulas
iVerify's findings indicate that all flaws (sandbox escape, privilege escalation, remote code execution) exploited in this exploit chain are known or documented, and Apple has already addressed them in the latest iOS releases.
The DarkSword exploit kit uses six vulnerabilities tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
## DarkSword attacks
In a report today, Google Threat Intelligence Group (GTIG) says that DarkSword has been used since at least November 2025 by several threat actors, who deployed three separate malware families:
GHOSTBLADE, a dataminer in JavaScript that steals a swath of information, including crypto wallet data, syst
Mandiant
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
blogs_mandiant·2026-03-18
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
DarkSword supports iOS vers
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
Threat Intelligence
# Look What You Made Us Patch: 2025 Zero-Days in Review
March 5, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
### Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
## Look What You Made Us Patch: 2025 Zero-Days in Review
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
## Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first identified in 2024, toward increased enterprise exploitation. Both
Bleepingcomputer
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
blogs_bleepingcomputer·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
## Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
## Lawrence Abrams
Apple says it is aware of reports that the flaw, along with the CVE-2025-14174 and CVE-2025-43529 flaws fixed in December , were exploited in the same incidents.
"An attacker with memory write capability may be able to execute arbitrary code," reads Apple's security bulletin .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report."
Apple says Google's Threat Analysis Group discovered CVE-2026-20700. The company did not provide any further details about how the vulnerability was exploited.
Affected
Checkpoint
15th December – Threat Intelligence Report
blogs_checkpoint·2025-12-15
CVE-2025-14174 15th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Indian government confirmed cyber incidents involving GPS spoofing at seven major airports, including Delhi, Mumbai, Kolkata, and Bengaluru. The attack affected aircrafts using GPS-based landing procedures. Despite signal disruption to navigation data, authorities stated no flights were cancelled or diverted, with c
Bleepingcomputer
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
blogs_bleepingcomputer·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Lawrence Abrams
CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group.
CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group.
Devices impacted by both flaws include:
iPhone 11 and later
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (8th generation and later)
iPad mini (5th generation and later)
Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·CVSS 7.8
CVE-2025-55182 [HIGH] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
# December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
- React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
- China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
- Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-conce
Wiz
CVE-2025-43529 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43529 [HIGH] CVE-2025-43529 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43529 :
Apple Safari vulnerability analysis and mitigation
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Source : NVD
## 8.8
Score
Published December 17, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
Apple Safari
Rocky Linux
Has Public Exploit Yes
Has CISA KEV Exploit Yes
Wiz
CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20700 [HIGH] CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20700 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Wiz
CVE-2025-14174 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-14174 [HIGH] CVE-2025-14174 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14174 :
vulnerability analysis and mitigation
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 8.8
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 75.2
Exploitation Probability (EPSS) 0.9
Affected packages and libraries
chromium
typelib-1_0-JavaScriptCore-4_0
Sources
Alpine 3.23, edge Severity HIGH Has Fix Added at: Jan 11, 2026
Chainguard Has Fix Added at: Dec 24, 2025
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Dec 18,
2025-12-12
Published
2025-12-12
Added to CISA KEV
Exploited in the wild