PT-2025-50966 · Google +4 · Google Chromium +6
Published
2025-12-10
·
Updated
2026-02-13
·
CVE-2025-14174
CVSS v2.0
10
10
High
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WebKitGTK versions 2.50.4-0ubuntu0.25.04.1
Google Chrome versions prior to 143.0.7499.110
Microsoft Edge versions prior to 143.0.7499.110
Opera versions prior to 125.0.5729.40
Opera GX versions prior to 125.0.5729.47
Opera Air versions prior to 125.0.5729.39
Safari versions prior to 26.2
WebKit2GTK (affected versions not specified)
wpewebkit (affected versions not specified)
Description
Multiple security issues were discovered in WebKitGTK, Google Chrome, Microsoft Edge, Opera, and Safari. These issues could allow a remote attacker to exploit a variety of vulnerabilities related to web browser security, including cross-site scripting, denial of service, and arbitrary code execution. A specific out-of-bounds memory access vulnerability (CVE-2025-14174) exists in ANGLE, a graphics library used by Chrome and other Chromium-based browsers. This vulnerability is actively exploited and could allow an attacker to perform out-of-bounds memory access via a crafted HTML page. The vulnerability stems from improper validation of memory boundaries during rendering operations. The vulnerability impacts browsers built on the Chromium open-source project.
Recommendations
Update WebKitGTK to version 2.50.4-0ubuntu0.25.04.1.
Update Google Chrome to version 143.0.7499.110 or later.
Update Microsoft Edge to version 143.0.7499.110 or later.
Update Opera to version 125.0.5729.40 or later.
Update Opera GX to version 125.0.5729.47 or later.
Update Opera Air to version 125.0.5729.39 or later.
Update Safari to version 26.2 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for WebKit2GTK and wpewebkit.
Fix
RCE
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
BDU:2026-00800
CVE-2025-14174
DLA-4414-1
DSA-6083-1
RHSA-2025:23663
RHSA-2025:23700
RHSA-2025:23967
RHSA-2025:23968
RHSA-2025:23969
RHSA-2025:23970
RHSA-2025:23971
RHSA-2025:23972
RHSA-2025:23973
RHSA-2025:23974
SUSE-SU-2025:4527-1
SUSE-SU-2025:4528-1
USN-7957-1
Affected Products
Angle
Debian
Google Chrome
Google Chromium
Linuxmint
Apple Macos
Ubuntu
References · 169
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-14174 · Security Note
- https://ubuntu.com/security/notices/USN-7957-1 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-14174 · Vendor Advisory
- https://osv.dev/vulnerability/UBUNTU-CVE-2025-14174 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-43541 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-43501 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-43535 · Vendor Advisory
- https://osv.dev/vulnerability/USN-7957-1 · Vendor Advisory
- https://bdu.fstec.ru/vul/2026-00800 · Security Note
- https://ubuntu.com/security/CVE-2025-43536 · Vendor Advisory
- https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2025:4527-1 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-14174 · Security Note
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security · Security Note
- https://cve.org/CVERecord?id=CVE-2025-14174 · Security Note