CVE-2025-14174
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium Out of Bounds Memory Access Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 23% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-787, CWE-119
מוצרים מושפעים
google: chrome; apple: macos; linux: linux kernel; microsoft: windows; apple: safari; apple: ipados; apple: iphone os; apple: tvos; apple: visionos; apple: watchos; microsoft: edge chromium
קישורים
- https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-deskto… Release Notes
- https://issues.chromium.org/issues/466192044 Permissions Required
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… Third Party Advisory