PT-2025-47797 · Apple · Mlx

Published

2025-11-21

·

Updated

2025-12-02

·

CVE-2025-62608

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions MLX versions prior to 0.29.4
Description MLX, an array framework for machine learning on Apple silicon, contains a heap buffer overflow in the mlx::core::load() function when processing malicious NumPy .npy files. A specially crafted file can trigger a 13-byte out-of-bounds read, potentially leading to a crash or information disclosure.
Recommendations Update to version 0.29.4 or later.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-62608
GHSA-W6VG-JG77-2QG6
PYSEC-2025-138

Affected Products

Mlx