HIGH
CVE-2025-14174
CVSS
8.8
KEV
Description
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Out of bounds memory access vulnerability in ANGLE (a graphics abstraction layer for WebGL) in Google Chrome on macOS before version 143.0.7499.110 allows a remote attacker to access memory outside allocated buffers via a maliciously crafted HTML page, potentially leading to memory corruption or information disclosure.
Mitigation
Update Google Chrome on Mac to version 143.0.7499.110 or later to patch the vulnerability. Organizations should verify all macOS endpoints have the updated browser version through their patch management infrastructure.
Weakness (CWE)
CWE-787
Out-of-bounds Write
CWE-119
Memory Buffer Bounds Error
EPSS Score
22.33%
Probability of exploitation in next 30 days
97.6th percentile
References
https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html
Release Notes
https://issues.chromium.org/issues/466192044
Permissions Required
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14174
Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.