
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14174 is a memory corruption vulnerability in WebKit (Apple's browser engine) and Google Chrome's ANGLE graphics layer that allows remote attackers to execute arbitrary code or disclose internal application states by processing maliciously crafted web content. It was reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on December 5, 2025, and publicly disclosed on December 10–12, 2025. Affected software includes Google Chrome before 143.0.7499.109/110, Microsoft Edge Chromium before 143.0.3650.80, Apple Safari before 26.2, iOS/iPadOS before 18.7.3 and 26.2, macOS before 26.2, watchOS before 26.2, tvOS before 26.2, and visionOS before 26.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory iOS 26.2, Chrome Release Blog).
The vulnerability has two distinct root causes depending on the affected component. In Google Chrome on macOS, it manifests as an out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine), Chrome's OpenGL ES translation layer (CWE-119/CWE-787). In Apple's WebKit, it is described as a memory corruption issue addressed with improved validation (WebKit Bugzilla: 303614), closely paired with a companion use-after-free vulnerability CVE-2025-43529 (WebKit Bugzilla: 302502). Exploitation requires user interaction — a victim must visit or be redirected to a maliciously crafted web page — making the attack vector network-based with low complexity. The vulnerability was discovered jointly by Apple SEAR and Google's Threat Analysis Group (TAG), indicating it was identified during active exploitation analysis. Public proof-of-concept repositories appeared on GitHub in early 2026 (Chrome Release Blog, Apple Advisory Safari 26.2).
Successful exploitation enables remote attackers to achieve arbitrary code execution on affected devices through maliciously crafted web content, with potential for complete device compromise including data theft and spyware installation. Apple confirmed the vulnerability was exploited in "extremely sophisticated attacks against specific targeted individuals" on iOS versions prior to iOS 26, indicating high-value targeting consistent with mercenary spyware operations. The vulnerability was subsequently incorporated into the Darksword iOS exploit kit — a multi-stage, six-vulnerability chain used by state-sponsored actors and spyware vendors — enabling full device takeover, theft of crypto wallets, personal data, and credentials (Apple Advisory iOS 26.2, Google GTIG Darksword Report).
com.apple.WebKit.WebContent or browser sandbox processes./tmp or app sandbox directories consistent with infostealer staging.Apple: Update to iOS/iPadOS 18.7.3 (for iOS 18.x devices) or iOS/iPadOS 26.2 (for iOS 26.x devices); update macOS, watchOS, tvOS, and visionOS to 26.2; update Safari to 26.2. Apple subsequently expanded iOS 18 security updates to additional older iPhone models to block Darksword attacks. Google Chrome: Update to version 143.0.7499.109 or later (released December 10, 2025). Microsoft Edge: Update to version 143.0.3650.80 or later (released December 15, 2025). As a temporary workaround, avoid visiting untrusted websites and consider enabling Lockdown Mode on iOS for high-risk individuals. Organizations should prioritize patching user-facing devices given active exploitation and CISA KEV status (Apple Advisory iOS 26.2, Chrome Release Blog, CISA KEV Alert).
Apple confirmed active exploitation in "extremely sophisticated attacks against specific targeted individuals" in its security advisories, language consistent with mercenary spyware disclosures. Google's Threat Analysis Group (TAG) co-discovered the vulnerability and later published a detailed report on the Darksword exploit kit that weaponized it. CISA issued an alert on December 12, 2025, adding the vulnerability to the KEV catalog and later ordering federal agencies to patch Darksword-related iOS flaws. Forbes, BleepingComputer, The Hacker News, The Register, and PCMag all covered the emergency patches extensively, with Forbes warning Chrome and Edge users that "attacks have started." Security researchers on Mastodon and Bluesky flagged the coordinated Apple/Google disclosure as significant. Lookout published threat intelligence linking CVE-2025-14174 to the Darksword exploit kit and GHOSTBLADE malware, while SentinelOne covered the weaponization in its weekly threat roundup (Google GTIG Darksword Report, BleepingComputer, Lookout Darksword Analysis).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."