CVE-2025-14174

9.5 CISA KEV

Google · Chrome

Google Chrome contains an out of bounds memory access vulnerability in the ANGLE component on macOS that allows remote attackers to trigger memory corruption via a crafted HTML page.

Executive summary

A critical out of bounds memory access vulnerability in Google Chrome is currently being exploited in the wild, posing a significant risk of remote code execution.

Vulnerability

This flaw exists within the ANGLE graphics engine component. It allows an unauthenticated remote attacker to perform out of bounds memory access by enticing a user to navigate to a specifically crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its critical severity and the potential for total system impact. Successful exploitation can lead to arbitrary code execution, resulting in full compromise of the user workstation, potential data exfiltration, and significant reputational or operational damage to the organization.

Remediation

Immediate Action: Update Google Chrome to version 143.0.7499.110 or later immediately across all macOS endpoints.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or crash reports related to the ANGLE graphics component.

Compensating Controls: While no direct substitute exists for patching, ensure that browser-based security policies are enforced and consider using endpoint detection and response (EDR) tools to monitor for suspicious child processes spawned by the browser.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub repositories.

Analyst recommendation

Due to the confirmed active exploitation and the critical nature of the memory access flaw, organizations must prioritize the deployment of the vendor-provided security update. Patch management teams should treat this as a top-priority item to prevent potential system compromise and data loss.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section, carried in 20 daily briefs, Dec 13 to Jan 1, 2026
  3. Analyst report written
  4. Fix documented version 143.0.7499.110 per CVE record

Sources