CVE-2025-14174
ENISA EUVD: EUVD-2025-203113 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
11 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.31%
probability
This CVE has a 0.31% probability
of being exploited in the next 30 days.
0%
Top 54.2th percentile of all CVEs
100%
CVSS v3.1
Source: NVD8.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroOOB write in libangle
Affected Products
Attack Intelligence
Google Project Zero
Patched
Dec. 12, 2025
Reported by
Apple and Google Threat Analysis Group
Root Cause Analysis
???
Exploits & PoC
George0Papasotiriou/CVE-2025-14174-Chrome-Zero-Day
PoC CVE-2025-14174 — George0Papasotiriou/CVE-2025-14174-Chrome-Zero-Day
3
1 repo — triés par ⭐
Rechercher sur GitHub ↗
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover
TheHackerNews
Mar 19, 2026
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
BleepingComputer
Feb 11, 2026
Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
TheHackerNews
Dec 11, 2025
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Other Devices
TheHackerNews
Feb 12, 2026
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
BleepingComputer
Dec 12, 2025
Google fixes eighth Chrome zero-day exploited in attacks in 2025
BleepingComputer
Dec 11, 2025
Apple discloses first actively exploited zero-day of 2026
CyberScoop
Feb 12, 2026
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
BleepingComputer
Apr 01, 2026
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
TheHackerNews
Dec 13, 2025
CVE-2025-14174 Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE
Microsoft-MSRC
Dec 15, 2025
CVE‑2025‑14174 Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE
Microsoft-MSRC
Dec 15, 2025
Signal Intelligence
Confidence
92%
EPSS
0.31%
CVSS v3.1
8.8
Mentions
11
Last Seen
Apr 01, 2026
CNA Information
Analyst Note
CVE-2025-14174 is confirmed as actively exploited in-the-wild with high severity (CVSS 8.8), reported by multiple credible sources including TheHackerNews documenting active exploitation. The vulnerability affects a widely-used component (ANGLE in Chrome) on macOS, and Google has issued an official patch, with evidence of sophisticated attack campaigns leveraging this flaw.
Threat Actors 5
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Mana Team
apt_group
🇨🇳 CN
Operation Triangulation
apt_group
Information theft and espionage
🇷🇺 RU
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026