NVD disclosure day

Published threat advisories for December 12, 2025

CVE advisoryKnown Exploit

CVE-2025-43510

Apple Operating System Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability in Apple operating systems could allow a malicious application to alter shared memory, potentially causing data integrity issues and system instability for affected organizations. This issue has been addressed in software updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-14611

Gladinet CentreStack and Triofox Cryptographic Weakness Affects File Access.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Gladinet CentreStack and Triofox have a security weakness in their encryption, potentially allowing unauthorized local file access and system compromise. This affects public-facing endpoints and requires immediate attention from affected organizations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-14174

Chrome Browser Memory Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A memory access vulnerability in Google Chrome's ANGLE component allows attackers to access memory via a crafted HTML page. This could impact organizations by affecting employees, systems, and data, posing a business risk. Organizations should prioritize addressing this.

• CISA KEV