CVE-2025-14174

high

Description

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

References

https://www.theregister.com/2026/02/12/apple_ios_263/

https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/

https://www.malwarebytes.com/blog/news/2026/02/apple-patches-zero-day-flaw-that-could-let-attackers-take-control-of-devices

https://www.helpnetsecurity.com/2026/02/12/apple-zero-day-fixed-cve-2026-20700/

https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html

https://securityaffairs.com/187890/security/apple-fixed-first-actively-exploited-zero-day-in-2026.html

https://cyberscoop.com/apple-zero-day-vulnerability-cve-2026-20700/

https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/

https://www.theregister.com/2025/12/15/apple_follows_google_by_emergency/

https://www.securityweek.com/apple-patches-two-zero-days-tied-to-mysterious-exploited-chrome-flaw/

https://www.helpnetsecurity.com/2025/12/15/ios-macos-cve-2025-14174-cve-2025-43529/

https://www.darkreading.com/vulnerabilities-threats/apple-patches-more-zero-days-sophisticated-attack

https://securityaffairs.com/185716/hacking/u-s-cisa-adds-apple-and-gladinet-centrestack-and-triofox-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://thehackernews.com/2025/12/apple-issues-security-updates-after-two.html

https://securityaffairs.com/185639/security/u-s-cisa-adds-google-chromium-and-sierra-wireless-airlink-aleos-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://securityaffairs.com/185628/hacking/emergency-fixes-deployed-by-google-and-apple-after-targeted-attacks.html

https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/

Details

Source: Mitre, NVD

Published: 2025-12-12

Updated: 2025-12-15

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.06224