cbcvebase.
CVE-2025-14174
published 2025-12-12

CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-01-02
Exploited in the wild
EPSS
22.72%
97.5th percentile
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.7.3_and_ipados
appleios_26.2_and_ipados
appleios_26.3_and_ipados
appleios_and_ipados< 26.326.3
appleipados< 18.7.318.7.3
appleipados< 26.326.3
appleipados>= 26.0 < 26.226.2
appleiphone_os< 18.7.318.7.3
appleiphone_os< 26.326.3
appleiphone_os>= 26.0 < 26.226.2
applemacos< 26.326.3
applemacos< 26.226.2
applemacos< 26.326.3
applemacos>= 26.0 < 26.226.2
applemacos_tahoe
applemacos_tahoe
applesafari< 26.226.2
applesafari
appletvos< 26.326.3
appletvos< 26.226.2
appletvos< 26.326.3
appletvos
appletvos
applevisionos< 26.326.3
applevisionos< 26.226.2

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-14174 is a use-after-free in WebKit (Apple) and an out-of-bounds memory access in ANGLE (Google Chrome on Mac); exploitation is triggered via processing maliciously crafted web content / a crafted HTML page delivered remotely.
  • The vulnerability was exploited in the wild as part of a chained, extremely sophisticated targeted attack alongside CVE-2025-43529 and CVE-2026-20700; detections should correlate exploitation of these three CVEs together.
  • Google's Threat Analysis Group (TAG) discovered the related CVE-2026-20700 exploit chain that includes CVE-2025-14174; TAG attribution suggests a nation-state or advanced threat actor targeting specific individuals.
  • The Chrome-side vector is the ANGLE graphics library used for WebGL; monitor for anomalous WebGL/ANGLE renderer crashes or memory access violations in Chrome on macOS prior to version 143.0.7499.110.
  • On the Apple side, the root cause is a use-after-free in WebKit; monitor for WebKit/Safari process crashes or unexpected memory write activity on unpatched iOS (<18.7.3 / <iOS 26), iPadOS, and macOS Tahoe devices.
  • ·CVE-2025-14174 maps to two distinct vulnerabilities in two separate products: an out-of-bounds memory access in ANGLE in Google Chrome on Mac (fixed in Chrome 143.0.7499.110), and a use-after-free in WebKit affecting Apple platforms (fixed in iOS 18.7.3, iPadOS 18.7.3, Safari 26.2, and macOS Tahoe 26.2). Detection rules must account for both codebases separately.
  • ·Exploitation has been confirmed in the wild (CISA KEV listed, Has Public Exploit: Yes per Wiz) and is described as part of 'extremely sophisticated' targeted attacks; patch prioritization should reflect active exploitation rather than CVSS score alone.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.