ZeroHour

CVE-2025-14174

KEVmass

Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera

CISA: Google Chromium Out of Bounds Memory Access Vulnerability

CVSS 3.1
8.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.

What to do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.

Affected
Google Chromium (ANGLE component)
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
Opera (Chromium-based)
Estimated exposure
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users) — Chromium is the dominant browser engine worldwide, powering Google Chrome (on the order of billions of users), Microsoft Edge, Opera, and many derivative browsers, so effectively the entire Chromium install base is exposed pending patching.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googleapplemicrosoft
Products
chrome, safari, ipados, iphone os, macos, tvos, visionos, watchos, edge chromium
Weakness
CWE-787, CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news