PT-2025-50966 · Google+4 · Google Chromium+6

Published

2025-12-10

·

Updated

2026-03-03

·

CVE-2025-14174

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebKitGTK versions prior to 2.50.4-0ubuntu0.25.04.1 Google Chrome versions prior to 143.0.7499.110 Microsoft Edge versions prior to 143.0.7499.110 Opera versions prior to 125.0.5729.49 Opera GX versions prior to 125.0.5729.47 Opera Air versions prior to 125.0.5729.39 Opera Neon versions prior to 125.0.5729.40 Apple Safari versions prior to 26.3 Apple iOS versions prior to 26.3 Apple macOS versions prior to 26.3 Apple tvOS versions prior to 26.3 Apple visionOS versions prior to 26.3 Apple watchOS versions prior to 26.3 Vivaldi versions prior to 125.0.5729.49
Description Multiple vulnerabilities were discovered in WebKitGTK and Chromium-based browsers, including Google Chrome, Microsoft Edge, Opera, and Apple Safari. These vulnerabilities allow a remote attacker to potentially execute arbitrary code, cause a denial of service, or perform out-of-bounds memory access via a crafted HTML page. The vulnerabilities stem from issues in the ANGLE graphics engine and improper authorization enforcement. The vulnerability CVE-2025-14174 is actively exploited in the wild. The flaw is related to an out-of-bounds memory access in ANGLE on macOS.
Recommendations Update WebKitGTK to version 2.50.4-0ubuntu0.25.04.1 or later. Update Google Chrome to version 143.0.7499.110 or later. Update Microsoft Edge to version 143.0.7499.110 or later. Update Opera to version 125.0.5729.49 or later. Update Opera GX to version 125.0.5729.47 or later. Update Opera Air to version 125.0.5729.39 or later. Update Opera Neon to version 125.0.5729.40 or later. Update Apple Safari to version 26.3 or later. Update Apple iOS to version 26.3 or later. Update Apple macOS to version 26.3 or later. Update Apple tvOS to version 26.3 or later. Update Apple visionOS to version 26.3 or later. Update Apple watchOS to version 26.3 or later. Update Vivaldi to version 125.0.5729.49 or later.

Fix

RCE

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-00800
CVE-2025-14174
DLA-4414-1
DSA-6083-1
RHSA-2025:23663
RHSA-2025:23700
RHSA-2025:23967
RHSA-2025:23968
RHSA-2025:23969
RHSA-2025:23970
RHSA-2025:23971
RHSA-2025:23972
RHSA-2025:23973
RHSA-2025:23974
SUSE-SU-2025:4527-1
SUSE-SU-2025:4528-1
USN-7957-1

Affected Products

Angle
Debian
Google Chrome
Google Chromium
Linuxmint
Apple Macos
Ubuntu