Heap Buffer Overflow Vulnerability in MLX Framework for Apple Silicon
CVE-2025-62608
5.5MEDIUM
What is CVE-2025-62608?
The MLX framework, designed for machine learning on Apple silicon, is susceptible to a heap buffer overflow that occurs in the mlx::core::load() function when processing specially crafted NumPy .npy files. This vulnerability allows an attacker to manipulate the input file, resulting in a 13-byte out-of-bounds read. Exploiting this issue may cause the application to crash or potentially leak sensitive information. Users are strongly advised to upgrade to version 0.29.4 or later, where this security flaw has been addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mlx < 0.29.4
References
CVSS V4
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
