CVE-2025-14174

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.

Researchers: Apple and Google Threat Analysis Group

Attribute Value
CVE CVE-2025-14174
Bugzilla 303614
Component WebKit
Bug Class LogicError
Severity medium
Advisory Apple Advisory

Fix not public. The WebKit fix for this bug is embargoed or not yet disclosed. The bug ID is confirmed from the Apple advisory, but no public commit references it.

Root Cause Analysis

A memory corruption issue was addressed with improved validation.