The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical zero-day vulnerability in Google Chromium to its Known Exploited Vulnerabilities (KEV) Catalog on December 12, 2025. This flaw is being actively exploited in the wild.
CVE-2025-14174 is an out-of-bounds memory access issue in Google Chromium. It can allow attackers to execute arbitrary code or cause crashes in affected browsers.
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks
CISA
Read the full CISA advisory here: