Security Affairs reports that the U.S. Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog to include flaws impacting Google Chromium and Sierra Wireless AirLink ALEOS, which must be remediated by federal civilian executive branch agencies by Jan. 2.The Chromium flaw, tracked as CVE-2025-14174 and also identified as Chromium issue 466192044, allows remote attackers to perform out-of-bounds memory access through crafted HTML pages. The vulnerability occurs in the ANGLE graphics library's Metal renderer due to incorrect buffer size calculations, which can result in memory corruption, crashes, or potential code execution. The Sierra Wireless flaw, CVE-2018-4063, affects the Airlink ES450 firmware upload.cgi component. Authenticated attackers can exploit it to upload and execute malicious code on the device's web server.CISA's directive follows Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, urging federal agencies to address these vulnerabilities and advising private organizations to review the KEV catalog to secure their networks.
Vulnerability Management, Patch/Configuration Management
Sierra Wireless, Chromium flaws added to CISA KEV list
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
