CVE-2025-14174

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*

History

15 Dec 2025, 15:16

Type Values Removed Values Added
CWE CWE-787
First Time Apple tvos
Microsoft edge Chromium
Microsoft
Apple safari
Google
Apple ipados
Linux linux Kernel
Apple watchos
Linux
Apple iphone Os
Google chrome
Microsoft windows
Apple visionos
Apple macos
Apple
References () https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html - () https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html - Release Notes
References () https://issues.chromium.org/issues/466192044 - () https://issues.chromium.org/issues/466192044 - Permissions Required
References () https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security - () https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14174 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14174 - Third Party Advisory
CPE cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

12 Dec 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-119
References
  • () https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security -
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14174 -

12 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-12 20:15

Updated : 2025-12-15 15:16


NVD link : CVE-2025-14174

Mitre link : CVE-2025-14174

CVE.ORG link : CVE-2025-14174


JSON object : View

Products Affected

apple

  • watchos
  • safari
  • iphone_os
  • visionos
  • tvos
  • ipados
  • macos

microsoft

  • edge_chromium
  • windows

google

  • chrome

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer