ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529)

criticalVulnerability exploited in the wildimportance 60CVE-2025-14174CVE-2025-43529

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14174
Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera

Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.

Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.

8.822% KEV
  • Google Chromium (ANGLE component)
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users)
CVE-2025-43529
Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution

CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile).

Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied.

8.89% KEV
  • Apple Safari All versions prior to Safari 26.2
  • Apple iPhone OS (iOS) Versions prior to iOS 26.2 (legacy branch fixed in iOS 18.7.3)
  • Apple iPadOS Versions prior to iPadOS 26.2 (legacy branch fixed in iPadOS 18.7.3)
  • +4 more
masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software
Full article393 words · extracted from helpnetsecurity.com · click to collapse

Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days.

Several days before the release of these updates, Google fixed CVE-2025-14174 in the desktop version of Chrome, though at the time the issue did not have a CVE number nor a description.

In the meantime, CVE-2025-14174 was revealed to be an “out of bounds memory access [flaw] in ANGLE in Google Chrome on Mac prior to 143.0.7499.110”, which “allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.”

CVE-2025-14174 has also been fixed by Microsoft in its Chromium-based Edge browser on December 11 and added to CISA’s Known Exploited Vulnerabilities catalog on December 12.

The vulnerabilities (CVE-2025-14174, CVE-2025-43529)

CVE-2025-14174 was reported to Google by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group (TAG) on December 5.

The notes accompanying Apple’s security updates released on December 12 offer more information: CVE-2025-14174 is a memory corruption issue in WebKit, an open-source web browser engine that’s used by Safari and all browsers on iPhone and iPad, which explains the need for Chrome and Edge fixes.

“Apple is aware of a report that [CVE-2025-14174] may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report,” Apple shared.

CVE-2025-14174 may lead to memory corruption, and CVE-2025-43529 (also in WebKit) may allow arbitrary code execution. Based on the available information, they might have been exploited in tandem, triggered by the browser processing a maliciously crafted web page.

As usual, details about the attacks are withheld, though the wording points to targeted attacks delivering spyware. Nevertheless, it’s a good idea for all users to update their Apple devices as quickly as possible.

CVE-2025-14174 and CVE-2025-43529 have been fixed in:

Users of macOS Sequoia (the v15 branch) and macOS Sonoma (v14) can upgrade to the latest OS versions and update Safari to v26.2 to remediate these vulnerabilities.

UPDATE (December 16, 2025, 05:50 a.m. ET):

CVE-2025-43529 has been added to CISA’s KEV catalog on December 15.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/15/ios-macos-cve-2025-14174-cve-2025-43529/