CVE-2025-14174

high

Description

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

References

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-darksword-ios-flaws-exploited-attacks/

https://securityaffairs.com/189716/security/apple-urges-iphone-users-to-update-as-coruna-and-darksword-exploit-kits-emerge.html

https://www.helpnetsecurity.com/2026/03/19/darksword-ios-exploit-iphone/

https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html

https://securityaffairs.com/189662/hacking/darksword-emerges-as-powerful-ios-exploit-tool-in-global-attacks.html

https://www.theregister.com/2026/03/18/darksword_exploit_kit_steals_iphone/

https://www.securityweek.com/darksword-ios-exploit-kit-used-by-state-sponsored-hackers-spyware-vendors/

https://www.darkreading.com/threat-intelligence/darksword-iphone-exploit-spies-thieves

https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/

https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/

https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review/

https://www.theregister.com/2026/02/12/apple_ios_263/

https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/

https://www.malwarebytes.com/blog/news/2026/02/apple-patches-zero-day-flaw-that-could-let-attackers-take-control-of-devices

https://www.helpnetsecurity.com/2026/02/12/apple-zero-day-fixed-cve-2026-20700/

https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html

https://securityaffairs.com/187890/security/apple-fixed-first-actively-exploited-zero-day-in-2026.html

https://cyberscoop.com/apple-zero-day-vulnerability-cve-2026-20700/

https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/

https://www.theregister.com/2025/12/15/apple_follows_google_by_emergency/

https://www.securityweek.com/apple-patches-two-zero-days-tied-to-mysterious-exploited-chrome-flaw/

https://www.helpnetsecurity.com/2025/12/15/ios-macos-cve-2025-14174-cve-2025-43529/

https://www.darkreading.com/vulnerabilities-threats/apple-patches-more-zero-days-sophisticated-attack

https://securityaffairs.com/185716/hacking/u-s-cisa-adds-apple-and-gladinet-centrestack-and-triofox-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://thehackernews.com/2025/12/apple-issues-security-updates-after-two.html

https://securityaffairs.com/185639/security/u-s-cisa-adds-google-chromium-and-sierra-wireless-airlink-aleos-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://securityaffairs.com/185628/hacking/emergency-fixes-deployed-by-google-and-apple-after-targeted-attacks.html

https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/

Details

Source: Mitre, NVD

Published: 2025-12-12

Updated: 2025-12-15

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.06224