LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-14174: Google Chromium Out of Bounds Memory Access Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 12, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 2, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-14174 to its Known Exploited Vulnerabilities catalog on Dec 12, 2025, with a federal patch deadline of Jan 2, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability…

Google Chromium contains an out of bounds memory access vulnerability in the ANGLE component. A remote attacker could exploit it by serving a crafted HTML page to a victim browser. This affects multiple Chromium-based browsers and requires attention from IT and security teams because it can lead to unauthorized memory access.

How it works

The vulnerability is an out of bounds memory access in ANGLE. An attacker can trigger this by delivering a specially crafted HTML page that the browser renders.

Technical readers should treat this as a classic memory-safety issue in a graphics translation layer. The browser processes untrusted web content and may read or write memory outside expected bounds.

Am I affected? How to find it in your systems

Chromium powers several common web browsers. Inventory all instances of Google Chrome, Microsoft Edge, Opera, and other Chromium-derived browsers in your environment. Confirm the presence of the vulnerability and affected versions against the vendor advisory.

How to remediate

Apply the update provided in the vendor advisory. Follow any additional instructions from the browser vendors.

If you can't patch immediately

Apply mitigations according to vendor instructions. Follow applicable BOD 22-01 guidance for cloud services. Discontinue use of the product if mitigations cannot be applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to data breaches. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium
Added to CISA KEVDec 12, 2025
Federal patch deadlineJan 2, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities