Skip to main content

CVE detail

CVE-2025-14174

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
23 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
23 source links · newest first
  • Apple warns that outdated iPhones are vulnerable to Coruna and DarkSword exploit kits and urges users to update iOS. Apple has warned that iPhones running outdated iOS versions are at risk from exploit kits like Coruna and DarkSword. These attacks use malicious web content to trigger infection chains that can steal sensitive data. Users are […]

    newssecurityaffairs.comMar 20, 2026, 11:22 AM
  • A powerful iPhone hacking toolkit dubbed “DarkSword” has been used since November 2025 to compromise devices by exploiting zero-day iOS vulnerabilities, Google researchers have shared. iOS vulnerabilities exploited by DarkSword Two weeks ago, Google Threat Intelligence Group (GTIG) and iVerify disclosed the existence of Coruna, a spy-grade iOS exploit kit that has been used in a commercial surveillance operation, by state-linked threat actors engaged in cyber espionage, and cybercriminals. While Coruna contains five full iOS … More →

    newswww.helpnetsecurity.comMar 19, 2026, 2:41 PM
  • DarkSword, a new iOS exploit kit, is used by multiple actors to steal data in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine. Lookout Threat Labs discovered a new iOS exploit kit called DarkSword that has been used since late 2025 by multiple threat actors, including surveillance vendors and likely nation-state actors. The toolkit enables […]

    newssecurityaffairs.comMar 19, 2026, 2:03 PM
  • Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.

    newswww.securityweek.comMar 18, 2026, 3:30 PM
  • e RCE exploit split across two files, rce_module.js and rce_worker_18.4.js (Figure 7). This exploit primarily leveraged CVE-2025-31277, a memory corruption vulnerability in JavaScriptCore (the JavaScript engine used in WebKit and Apple Safari), and also CVE-2026-20700, a Pointer Authentication Codes (PAC) bypass in dyld . We then identified activity se

    vendorcloud.google.comMar 18, 2026, 2:00 PM
  • Apple issued security updates for all devices which include a patch for an actively exploited zero-day—tracked as CVE-2026-20700.

    newswww.malwarebytes.comFeb 12, 2026, 11:40 AM
  • Apple has released fixes for a zero-day vulnerability (CVE-2026-20700) exploited in targeted attacks last year. CVE-2026-20700 is a memory corruption issue in dyld, the Dynamic Link Editor component of Apple’s operating systems, and may allow attackers with memory write capability to execute arbitrary code. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26,” the company … More →

    newswww.helpnetsecurity.comFeb 12, 2026, 10:55 AM
  • Apple fixed an exploited zero-day in iOS, macOS, and other devices that allowed attackers to run code via a memory flaw. Apple released updates for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS to address an actively exploited zero-day tracked as CVE-2026-20700. The flaw is a memory corruption issue in Apple’s Dynamic Link Editor (dyld) that […]

    newssecurityaffairs.comFeb 12, 2026, 10:50 AM
  • Impacting the ‘dyld’ system component, the memory corruption issue can be exploited for arbitrary code execution.

    newswww.securityweek.comFeb 12, 2026, 7:48 AM
  • Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and evolution of patch management, and finally yes, provide a forecast of what security patches are expected to release next week on Patch Tuesday. Microsoft reported several issues you should be aware of with respect to the … More →

    newswww.helpnetsecurity.comJan 9, 2026, 8:24 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How researchers are teaching AI agents to ask for permission the right way People are starting to hand more decisions to AI agents, from booking trips to sorting digital files. The idea sounds simple. Tell the agent what you want, then let it work through the steps. The hard part is what the agent does with personal data along the … More →

    newswww.helpnetsecurity.comDec 21, 2025, 9:00 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: Last week, Apple and […]

    newssecurityaffairs.comDec 15, 2025, 6:59 PM
  • 15th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 15th December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Indian government confirmed cyber incidents involving GPS spoofing at seven major airports, including Delhi, Mumbai, Kolkata, and Bengaluru. The attack affected aircrafts using GPS-based landing procedures. Despite signal disruption to navigation […]

    vendorresearch.checkpoint.comDec 15, 2025, 1:03 PM
  • Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days. Several days before the release of these updates, Google fixed CVE-2025-14174 in the desktop version of Chrome, though at the time the issue did not have a CVE number nor a description. In the meantime, CVE-2025-14174 was revealed to be an “out of bounds memory access [flaw] in ANGLE in Google Chrome on Mac prior to … More →

    newswww.helpnetsecurity.comDec 15, 2025, 10:58 AM
  • Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack.

    newswww.securityweek.comDec 15, 2025, 8:47 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2025-14174 is an […]

    newssecurityaffairs.comDec 13, 2025, 10:48 AM
  • Google and Apple issued emergency updates to address zero-day flaws exploited in attacks targeting an unknown number of users. Apple and Google have both pushed out urgent security updates after uncovering a highly targeted attacks against an unknown number of users. The attacks abused zero‑day vulnerabilities in their software. The campaign appears to involve nation-state […]

    newssecurityaffairs.comDec 13, 2025, 12:08 AM
  • No excerpt available.

    Mitigationwww.cisa.govDec 12, 2025, 8:15 PM
  • No excerpt available.

    Third Party Advisorylearn.microsoft.comDec 12, 2025, 8:15 PM
  • https://issues.chromium.org/issues/466192044issues.chromium.org

    No excerpt available.

    Exploitissues.chromium.orgDec 12, 2025, 8:15 PM
  • https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.htmlchromereleases.googleblog.com

    No excerpt available.

    Vendor Advisorychromereleases.googleblog.comDec 12, 2025, 8:15 PM
  • If we’re lucky, this update will close out 2025’s run of Chrome zero-days. This one is a V8 type-confusion issue already being exploited in the wild.

    newswww.malwarebytes.comDec 11, 2025, 11:58 AM
  • The Chrome zero-day does not have a CVE and it’s unclear who reported it and which browser component it affects.

    newswww.securityweek.comDec 11, 2025, 7:43 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence