CISA Flags Actively Exploited Chromium Zero-Day Threat

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical zero-day vulnerability in Google Chrome that is being actively exploited in the wild.

The flaw, tracked as CVE-2025-14174, poses a significant risk to millions of users across multiple web browsers and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Details and Impact

Security researchers discovered an out-of-bounds memory access vulnerability within ANGLE (Almost Native Graphics Layer Engine), a critical component of the Chromium rendering engine.

This flaw enables remote attackers to execute malicious code through specially crafted HTML pages, potentially compromising systems without user interaction.

The vulnerability affects numerous Chromium-based browsers beyond Google Chrome, including Microsoft Edge, Opera, Brave, and other derivatives that rely on the same rendering engine.​

The widespread adoption of Chromium makes this vulnerability particularly concerning for both enterprise environments and individual users.

Out-of-bounds memory access vulnerabilities in rendering engines are especially dangerous because they allow attackers to read or write data outside allocated memory boundaries, potentially leading to arbitrary code execution, data exfiltration, or complete system compromise.

The ANGLE component, which translates OpenGL ES API calls to DirectX, Vulkan, or desktop OpenGL, presents a critical attack surface because it processes graphics content from untrusted web sources.

CISA added CVE-2025-14174 to its Known Exploited Vulnerabilities catalog on December 12, 2025, mandating federal agencies to take immediate action.

Organizations must apply available patches or implement vendor-specified mitigations by January 2, 2026, in accordance with the guidance in Binding Operational Directive 22-01.

This directive requires federal civilian executive branch agencies to remediate identified vulnerabilities within prescribed timeframes, though CISA strongly recommends all organizations prioritize timely remediation of these catalog vulnerabilities to reduce exposure to cyberattacks.

System administrators and security teams should prioritize updating all Chromium-based browsers to the latest versions immediately.

Google released Chrome version 131.0.6778.264 on December 12, 2025, which addresses this vulnerability.

Users can verify their browser version and initiate updates by navigating to Settings, selecting “About Chrome,” and allowing the automatic update process to complete.

Other Chromium-based browser vendors, including Microsoft, Opera, Brave, and Vivaldi, are expected to incorporate the fix into their respective update channels shortly.

For environments where immediate patching is not feasible, CISA recommends implementing network-level protections, restricting browser execution via application control policies, or temporarily migrating to alternative browsers not based on Chromium until mitigations are deployed.

Security teams should monitor for suspicious execution of HTML files and implement endpoint detection rules to identify potential exploitation attempts.

Organizations should also review their vulnerability management frameworks to ensure they incorporate CISA’s KEV catalog as a prioritization input to enable more effective resource allocation against actively exploited threats.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories