U.S. CISA adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-4063 | Unrestricted File Upload Leading to Code Execution in Sierra Wireless AirLink ALEOS CVE-2018-4063 is an unrestricted upload of a file with a dangerous type (CWE-434) in the web server of Sierra Wireless AirLink gateways running ALEOS, where a specially crafted HTTP request can upload an executable file that becomes routable and accessible through the webserver. The flaw is triggered by an authenticated HTTP request, so an attacker must first have valid credentials for the device's web interface. With that access, an attacker can place executable code on the gateway and run it through the webserver, effectively achieving authenticated remote code execution on a device that often sits at the network edge of critical operations. Any organization running AirLink ALEOS gateways is potentially affected, and CISA notes that the impacted product may be end-of-life or end-of-service, with the recommended action being to discontinue use where mitigations are not available. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-12, indicating known exploitation in the wild, with a high EPSS score (27.1%, 98th percentile), no public proof-of-concept, and unknown ransomware usage. Do: Inventory all AirLink gateways running ALEOS and check their ALEOS firmware versions against Sierra Wireless/Semtech advisories, then upgrade to currently supported firmware or discontinue use of any device CISA notes as EoL/EoS. Restrict the gateway web management interface to trusted management networks, rotate device credentials since authentication is required for exploitation, and look for unexpected uploaded files on the device webserver. Federal agencies must apply this fix per BOD 22-01 guidance following the 2025-12-12 KEV addition. | 8.8 | 27% | KEV PoC ×3 |
| largetens of thousands of exposed AirLink gateways, with the total deployed fleet plausibly in the hundreds of thousands | |
| CVE-2025-14174 | Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet. Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations. | 8.8 | 22% | KEV |
| massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users) |
Full article368 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 13, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2025-14174 Google Chromium Out-of-Bounds Memory Access Vulnerability;
- CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability;
CVE-2025-14174 is an out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110. A remote attacker can exploit the flaw to perform out of bounds memory access via a crafted HTML page.
This week Google released security updates to fix three vulnerabilities in the Chrome browser, including this high-severity flaw that threat actors are already exploiting in real-world attacks.
“Google is aware that an exploit for 466192044 exists in the wild,” reads the advisory published by Google.
Google tracked the high-severity vulnerability as Chromium issue 466192044, but the IT giant did not share technical details about the bug. A related GitHub commit, however, reveals the bug lies in the ANGLE graphics library, specifically its Metal renderer, where buffer sizes were incorrectly calculated using pixelsDepthPitch, derived from GL_UNPACK_IMAGE_HEIGHT. Because this value may be smaller than the actual image height, it can cause buffer overflows, leading to memory corruption, crashes, or potentially arbitrary code execution.
CVE-2018-4063 is a remote code execution flaw in Sierra Wireless AirLink ES450 FW 4.9.3 that affects the upload.cgi component. An authenticated attacker can send a crafted HTTP request to upload and execute malicious code on the device’s web server.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by January 2nd, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185639/security/u-s-cisa-adds-google-chromium-and-sierra-wireless-airlink-aleos-flaws-to-its-known-exploited-vulnerabilities-catalog.html