CVE-2025-14174: Google Chromium Out of Bounds Memory Access Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-12-12. EPSS: 22.3% chance of exploitation in the next 30 days.
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Affected products
- Apple iPadOS: before 18.7.3 (fixed in 18.7.3); from 26.0, before 26.2 (fixed in 26.2)
- Apple iPhone OS: before 18.7.3 (fixed in 18.7.3); from 26.0, before 26.2 (fixed in 26.2)
- Apple macOS: before 26.2 (fixed in 26.2)
- Apple Safari: before 26.2 (fixed in 26.2)
- Apple tvOS: before 26.2 (fixed in 26.2)
- Apple visionOS: before 26.2 (fixed in 26.2)
- Apple watchOS: before 26.2 (fixed in 26.2)
- Google Chrome: from 143.0.7499.41, before 143.0.7499.110 (fixed in 143.0.7499.110); from 143.0.7499.40, before 143.0.7499.109 (fixed in 143.0.7499.109); up to and including 143.0.7499.40
- Microsoft Edge Chromium: before 143.0.3650.80 (fixed in 143.0.3650.80)
Published 2025-12-12. Last modified 2026-10-07.