CISA has added the Google Chromium vulnerability CVE-2025-14174 to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. This high-severity flaw, found in the ANGLE graphics abstraction layer used by Chromium-based browsers, allows out-of-bounds memory access due to improper buffer sizing in the Metal renderer. The vulnerability affects Google Chrome on macOS prior to version 143.0.7499.110, with related fixes also applied to Windows and Linux builds. Exploitation of this vulnerability can lead to memory corruption, browser crashes, or potentially arbitrary code execution within the browser context.
Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch agencies are required to remediate this vulnerability by the specified deadline, while CISA strongly encourages all organizations to prioritize patching. The addition of CVE-2025-14174 to the KEV catalog highlights its active exploitation and the significant risk it poses to federal and other enterprise environments. Organizations are urged to update affected systems promptly to mitigate the threat posed by this vulnerability.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were required to remediate the newly listed KEV vulnerabilities by January 2, 2026. CISA also urged all organizations to prioritize patching to reduce exposure to active exploitation.
CISA added Sierra Wireless AirLink ALEOS flaw CVE-2018-4063 and Google Chromium flaw CVE-2025-14174 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The KEV additions made both issues priority remediation items for federal agencies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.