CVE-2025-62608Critical· 9.1▾ MidnightMLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue has been patched in version 0.29.4.
mlx < 0.29.4Upgrade past the affected range:
mlx 0.29.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62609High· 7.5MLX is an array framework for machine learning on Apple silicon
CVE-2026-25243High· 8.8Redis is an in-memory data structure store
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-23534Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-23533Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-23532Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol