Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Is CVE-2025-14174 exploited?
Listed in the CISA KEV catalog on 2025-12-12.
Federal remediation due 2026-01-02.
Past that date by 225 days.
EPSS puts exploitation in the next 30 days at 23%.
Public exploit code: none found in monitored sources.