Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14174

Опубликовано: 12 дек. 2025
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

A flaw was found in ANGLE in Google Chrome. This vulnerability allows a remote attacker to perform out of bounds memory access via a crafted HTML (HyperText Markup Language) page. Although this was reported on Google Chrome, this issue also affected the WebKitGTK package with the same possible outcome.

Отчет

This vulnerability is rated as Important by the Red Hat Product Security. A maliciously crafted web page may lead to out of bound memory access, specially in WebKitGTK component, and may be leverage to perform a remote code execution. For an attack be successfully performed, the user needs to be tricked to visit the malicious web page using the affected component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9thunderbirdNot affected
Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4FixedRHSA-2025:2397524.12.2025
Red Hat Enterprise Linux 8webkit2gtk3FixedRHSA-2025:2366318.12.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-823
https://bugzilla.redhat.com/show_bug.cgi?id=2421824Google Chrome: chromium: webkitgtk: Out of bounds memory access via crafted HTML page

EPSS

Процентиль: 98%
0.22632
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
8 месяцев назад

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
8 месяцев назад

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

msrc
8 месяцев назад

Chromium: CVE-2025-14174 Out of bounds memory access in ANGLE

CVSS3: 8.8
debian
8 месяцев назад

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to ...

CVSS3: 8.8
github
8 месяцев назад

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 98%
0.22632
Средний

8.8 High

CVSS3