CVE-2025-14174: Google Chromium Out of Bounds Memory Access Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-12-12. EPSS: 22.3% chance of exploitation in the next 30 days.

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Affected products

  • Apple iPadOS: before 18.7.3 (fixed in 18.7.3); from 26.0, before 26.2 (fixed in 26.2)
  • Apple iPhone OS: before 18.7.3 (fixed in 18.7.3); from 26.0, before 26.2 (fixed in 26.2)
  • Apple macOS: before 26.2 (fixed in 26.2)
  • Apple Safari: before 26.2 (fixed in 26.2)
  • Apple tvOS: before 26.2 (fixed in 26.2)
  • Apple visionOS: before 26.2 (fixed in 26.2)
  • Apple watchOS: before 26.2 (fixed in 26.2)
  • Google Chrome: from 143.0.7499.41, before 143.0.7499.110 (fixed in 143.0.7499.110); from 143.0.7499.40, before 143.0.7499.109 (fixed in 143.0.7499.109); up to and including 143.0.7499.40
  • Microsoft Edge Chromium: before 143.0.3650.80 (fixed in 143.0.3650.80)

Published 2025-12-12. Last modified 2026-10-07.