CVE-2025-14174
vulnerability analysis and mitigation

Overview

CVE-2025-14174 is a memory corruption vulnerability in WebKit (Apple's browser engine) and Google Chrome's ANGLE graphics layer that allows remote attackers to execute arbitrary code or disclose internal application states by processing maliciously crafted web content. It was reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on December 5, 2025, and publicly disclosed on December 10–12, 2025. Affected software includes Google Chrome before 143.0.7499.109/110, Microsoft Edge Chromium before 143.0.3650.80, Apple Safari before 26.2, iOS/iPadOS before 18.7.3 and 26.2, macOS before 26.2, watchOS before 26.2, tvOS before 26.2, and visionOS before 26.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory iOS 26.2, Chrome Release Blog).

Technical details

The vulnerability has two distinct root causes depending on the affected component. In Google Chrome on macOS, it manifests as an out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine), Chrome's OpenGL ES translation layer (CWE-119/CWE-787). In Apple's WebKit, it is described as a memory corruption issue addressed with improved validation (WebKit Bugzilla: 303614), closely paired with a companion use-after-free vulnerability CVE-2025-43529 (WebKit Bugzilla: 302502). Exploitation requires user interaction — a victim must visit or be redirected to a maliciously crafted web page — making the attack vector network-based with low complexity. The vulnerability was discovered jointly by Apple SEAR and Google's Threat Analysis Group (TAG), indicating it was identified during active exploitation analysis. Public proof-of-concept repositories appeared on GitHub in early 2026 (Chrome Release Blog, Apple Advisory Safari 26.2).

Impact

Successful exploitation enables remote attackers to achieve arbitrary code execution on affected devices through maliciously crafted web content, with potential for complete device compromise including data theft and spyware installation. Apple confirmed the vulnerability was exploited in "extremely sophisticated attacks against specific targeted individuals" on iOS versions prior to iOS 26, indicating high-value targeting consistent with mercenary spyware operations. The vulnerability was subsequently incorporated into the Darksword iOS exploit kit — a multi-stage, six-vulnerability chain used by state-sponsored actors and spyware vendors — enabling full device takeover, theft of crypto wallets, personal data, and credentials (Apple Advisory iOS 26.2, Google GTIG Darksword Report).

Exploitation steps

  1. Reconnaissance: Identify target individuals using unpatched iOS (pre-iOS 26 / pre-18.7.3) or Chrome (pre-143.0.7499.109) devices. The Darksword campaign targeted high-value individuals; attackers used tools like Shodan or social profiling to identify targets.
  2. Delivery: Craft or compromise a legitimate website to serve malicious JavaScript. The Darksword exploit chain used pure JavaScript delivered via legitimate-appearing websites to avoid detection.
  3. Initial exploitation (ANGLE/WebKit trigger): Deliver a crafted HTML page containing a malicious payload targeting the out-of-bounds memory access in Chrome's ANGLE layer (on macOS) or the WebKit memory corruption flaw. The payload triggers improper memory handling when the browser processes specific graphics or web content operations.
  4. Memory corruption: The out-of-bounds write or uninitialized memory access corrupts adjacent heap memory, enabling controlled memory manipulation. In the Darksword chain, CVE-2025-14174 was chained with CVE-2025-43529 (WebKit use-after-free) to achieve reliable code execution.
  5. Code execution: The chained exploit achieves arbitrary code execution in the browser/WebKit process context, enabling the attacker to escape the sandbox using additional privilege escalation vulnerabilities in the Darksword chain (6 total flaws, 3 zero-days).
  6. Payload deployment: Deploy infostealer malware (GHOSTBLADE) or spyware to exfiltrate personal data, crypto wallet credentials, and device information (Google GTIG Darksword Report, Chrome Release Blog).

Indicators of compromise

  • Network: Unusual outbound connections from Safari/WebKit or Chrome processes to unknown external IPs; HTTP/HTTPS requests to newly registered or compromised domains serving obfuscated JavaScript; traffic patterns consistent with multi-stage exploit delivery (sequential resource fetching from exploit infrastructure).
  • Process: Unexpected child processes spawned by Safari, WebKit, or Chrome renderer processes (e.g., shell commands, data exfiltration utilities); unusual process activity from com.apple.WebKit.WebContent or browser sandbox processes.
  • File System: Presence of unknown executables or dylibs in temporary directories or app containers; new configuration profiles installed without user consent; unexpected files in /tmp or app sandbox directories consistent with infostealer staging.
  • Logs: Crash logs or WebKit/ANGLE-related memory access violations in system diagnostic logs; unusual JavaScript execution patterns in browser logs; iOS syslog entries showing unexpected process launches from browser contexts.
  • Behavioral: Unexplained battery drain or data usage spikes; device behaving abnormally after visiting a specific website; Apple threat notification received (Apple notified targeted individuals via Lockdown Mode alerts) (Google GTIG Darksword Report, Lookout Darksword Analysis).

Mitigation and workarounds

Apple: Update to iOS/iPadOS 18.7.3 (for iOS 18.x devices) or iOS/iPadOS 26.2 (for iOS 26.x devices); update macOS, watchOS, tvOS, and visionOS to 26.2; update Safari to 26.2. Apple subsequently expanded iOS 18 security updates to additional older iPhone models to block Darksword attacks. Google Chrome: Update to version 143.0.7499.109 or later (released December 10, 2025). Microsoft Edge: Update to version 143.0.3650.80 or later (released December 15, 2025). As a temporary workaround, avoid visiting untrusted websites and consider enabling Lockdown Mode on iOS for high-risk individuals. Organizations should prioritize patching user-facing devices given active exploitation and CISA KEV status (Apple Advisory iOS 26.2, Chrome Release Blog, CISA KEV Alert).

Community reactions

Apple confirmed active exploitation in "extremely sophisticated attacks against specific targeted individuals" in its security advisories, language consistent with mercenary spyware disclosures. Google's Threat Analysis Group (TAG) co-discovered the vulnerability and later published a detailed report on the Darksword exploit kit that weaponized it. CISA issued an alert on December 12, 2025, adding the vulnerability to the KEV catalog and later ordering federal agencies to patch Darksword-related iOS flaws. Forbes, BleepingComputer, The Hacker News, The Register, and PCMag all covered the emergency patches extensively, with Forbes warning Chrome and Edge users that "attacks have started." Security researchers on Mastodon and Bluesky flagged the coordinated Apple/Google disclosure as significant. Lookout published threat intelligence linking CVE-2025-14174 to the Darksword exploit kit and GHOSTBLADE malware, while SentinelOne covered the weaponization in its weekly threat roundup (Google GTIG Darksword Report, BleepingComputer, Lookout Darksword Analysis).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management