CVE detail
CVE-2025-14174
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
23 source links · newest first
Apple warns that outdated iPhones are vulnerable to Coruna and DarkSword exploit kits and urges users to update iOS. Apple has warned that iPhones running outdated iOS versions are at risk from exploit kits like Coruna and DarkSword. These attacks use malicious web content to trigger infection chains that can steal sensitive data. Users are […]
newssecurityaffairs.comMar 20, 2026, 11:22 AM- DarkSword: Researchers uncover another iOS exploit kitHelp Net Security
A powerful iPhone hacking toolkit dubbed “DarkSword” has been used since November 2025 to compromise devices by exploiting zero-day iOS vulnerabilities, Google researchers have shared. iOS vulnerabilities exploited by DarkSword Two weeks ago, Google Threat Intelligence Group (GTIG) and iVerify disclosed the existence of Coruna, a spy-grade iOS exploit kit that has been used in a commercial surveillance operation, by state-linked threat actors engaged in cyber espionage, and cybercriminals. While Coruna contains five full iOS … More →
newswww.helpnetsecurity.comMar 19, 2026, 2:41 PM - DarkSword emerges as powerful iOS exploit tool in global attacksSecurity Affairs
DarkSword, a new iOS exploit kit, is used by multiple actors to steal data in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine. Lookout Threat Labs discovered a new iOS exploit kit called DarkSword that has been used since late 2025 by multiple threat actors, including surveillance vendors and likely nation-state actors. The toolkit enables […]
newssecurityaffairs.comMar 19, 2026, 2:03 PM Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.
newswww.securityweek.comMar 18, 2026, 3:30 PMe RCE exploit split across two files, rce_module.js and rce_worker_18.4.js (Figure 7). This exploit primarily leveraged CVE-2025-31277, a memory corruption vulnerability in JavaScriptCore (the JavaScript engine used in WebKit and Apple Safari), and also CVE-2026-20700, a Pointer Authentication Codes (PAC) bypass in dyld . We then identified activity se
vendorcloud.google.comMar 18, 2026, 2:00 PMApple issued security updates for all devices which include a patch for an actively exploited zero-day—tracked as CVE-2026-20700.
newswww.malwarebytes.comFeb 12, 2026, 11:40 AMApple has released fixes for a zero-day vulnerability (CVE-2026-20700) exploited in targeted attacks last year. CVE-2026-20700 is a memory corruption issue in dyld, the Dynamic Link Editor component of Apple’s operating systems, and may allow attackers with memory write capability to execute arbitrary code. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26,” the company … More →
newswww.helpnetsecurity.comFeb 12, 2026, 10:55 AM- Apple fixed first actively exploited zero-day in 2026Security Affairs
Apple fixed an exploited zero-day in iOS, macOS, and other devices that allowed attackers to run code via a memory flaw. Apple released updates for iOS, iPadOS, macOS, watchOS, tvOS, and visionOS to address an actively exploited zero-day tracked as CVE-2026-20700. The flaw is a memory corruption issue in Apple’s Dynamic Link Editor (dyld) that […]
newssecurityaffairs.comFeb 12, 2026, 10:50 AM Impacting the ‘dyld’ system component, the memory corruption issue can be exploited for arbitrary code execution.
newswww.securityweek.comFeb 12, 2026, 7:48 AM- January 2026 Patch Tuesday forecast: And so it continuesHelp Net Security
Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and evolution of patch management, and finally yes, provide a forecast of what security patches are expected to release next week on Patch Tuesday. Microsoft reported several issues you should be aware of with respect to the … More →
newswww.helpnetsecurity.comJan 9, 2026, 8:24 AM - Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 releasedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How researchers are teaching AI agents to ask for permission the right way People are starting to hand more decisions to AI agents, from booking trips to sorting digital files. The idea sounds simple. Tell the agent what you want, then let it work through the steps. The hard part is what the agent does with personal data along the … More →
newswww.helpnetsecurity.comDec 21, 2025, 9:00 AM - U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: Last week, Apple and […]
newssecurityaffairs.comDec 15, 2025, 6:59 PM - 15th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 15th December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Indian government confirmed cyber incidents involving GPS spoofing at seven major airports, including Delhi, Mumbai, Kolkata, and Bengaluru. The attack affected aircrafts using GPS-based landing procedures. Despite signal disruption to navigation […]
vendorresearch.checkpoint.comDec 15, 2025, 1:03 PM - Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529)Help Net Security
Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days. Several days before the release of these updates, Google fixed CVE-2025-14174 in the desktop version of Chrome, though at the time the issue did not have a CVE number nor a description. In the meantime, CVE-2025-14174 was revealed to be an “out of bounds memory access [flaw] in ANGLE in Google Chrome on Mac prior to … More →
newswww.helpnetsecurity.comDec 15, 2025, 10:58 AM Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack.
newswww.securityweek.comDec 15, 2025, 8:47 AM- U.S. CISA adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2025-14174 is an […]
newssecurityaffairs.comDec 13, 2025, 10:48 AM Google and Apple issued emergency updates to address zero-day flaws exploited in attacks targeting an unknown number of users. Apple and Google have both pushed out urgent security updates after uncovering a highly targeted attacks against an unknown number of users. The attacks abused zero‑day vulnerabilities in their software. The campaign appears to involve nation-state […]
newssecurityaffairs.comDec 13, 2025, 12:08 AMNo excerpt available.
Mitigationwww.cisa.govDec 12, 2025, 8:15 PMNo excerpt available.
Third Party Advisorylearn.microsoft.comDec 12, 2025, 8:15 PM- https://issues.chromium.org/issues/466192044issues.chromium.org
No excerpt available.
Exploitissues.chromium.orgDec 12, 2025, 8:15 PM - https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.htmlchromereleases.googleblog.com
No excerpt available.
Vendor Advisorychromereleases.googleblog.comDec 12, 2025, 8:15 PM - [Updated] Another Chrome zero-day under attack: update nowMalwarebytes Labs
If we’re lucky, this update will close out 2025’s run of Chrome zero-days. This one is a V8 type-confusion issue already being exploited in the wild.
newswww.malwarebytes.comDec 11, 2025, 11:58 AM The Chrome zero-day does not have a CVE and it’s unclear who reported it and which browser component it affects.
newswww.securityweek.comDec 11, 2025, 7:43 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-43810CVSS 9.8 · Critical
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, vis…
- CVE-2026-20698CVSS 7.8 · High
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be abl…
- CVE-2025-43433CVSS 8.8 · High
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, vis…
- CVE-2025-43431CVSS 8.8 · High
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, vis…
- CVE-2026-28859CVSS 4.3 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A ma…
- CVE-2026-20635CVSS 4.3 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, vis…