CVE-2026-14174Patch

MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

5.5/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-03-05)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-16: 1Mentions · 2026-03-05: 2PoC Mentioned / Linked · 2026-03-05: 1Active Exploitation · 2026-02-16: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-03-05: 2Technical Details · 2026-02-16: 1Technical Details · 2026-03-05: 202-1603-05
Signal classification1 categories
Patch
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-161
Patch1
2026-03-052
Patch2
Full discourse3 posts
  • Zero Day Engineering@zerodaytraining
    Patch

    Apple recently patched the missing piece in the userland part of the Dec'25 full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet). Patched in iOS 26.3

    Post summary

    Apple has patched CVE-2026-20700— a dyld memory corruption that enabled PAC bypass— as part of completing the Dec'25 full-chain exploit, with the fix applied in iOS 26.3.

    22301827919.7K
    10.3K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    Apple recently patched the missing piece in the userland part of the full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet) Patched

    Post summary

    Apple has issued a patch for CVE‑2026‑20700, completing a chain of related exploits. A public PoC exists for CVE‑2026‑43529, but not yet for the other chain members.

    08058225.3K
    1.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome Zero-Day CVE-2026-2441 Exploited in the Wild — Patch Now Google shipped fixes for CVE-2026-2441, a high-severity use-after-free in Chrome’s CSS component that can be triggered by a crafted HTML page to run attacker code inside the browser sandbox; exploitation is confirmed in-the-wild and impacts any endpoint not yet on the fixed Stable builds (Win/macOS 145.0.7632.75/76, Linux 144.0.7559.75) or that updated but hasn’t restarted Chrome. Prioritize rapid browser version compliance and restart enforcement across fleets to close this drive-by initial access path. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://socprime.com/blog/cve-2026-14174-vulnerability/

    Post summary

    Chrome’s CVE‑2026‑2441, a high‑severity use‑after‑free exploited in the wild, has been patched by Google; users must update and restart browsers to mitigate the risk.

    0000039
    176 followersView on X

Explore more