PT-2025-47798 · Apple+1 · Mlx+1

Published

2025-11-21

·

Updated

2025-12-02

·

CVE-2025-62609

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MLX versions prior to 0.29.4
Description MLX, an array framework for machine learning on Apple silicon, contains a flaw in the mlx::core::load gguf() function. This function experiences a segmentation fault when processing maliciously crafted GGUF files. The issue stems from dereferencing an untrusted pointer originating from the external gguflib library without proper validation, leading to application crashes.
Recommendations Update to version 0.29.4 or later.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-62609
GHSA-J842-XGM4-WF88
PYSEC-2025-139

Affected Products

Mlx
Gguflib