Segmentation Fault Vulnerability in MLX Machine Learning Framework by Apple
CVE-2025-62609

5.5MEDIUM

Key Information:

Vendor

Ml-explore

Status
Vendor
CVE Published:
21 November 2025

What is CVE-2025-62609?

The MLX framework, utilized for machine learning on Apple silicon, is susceptible to a segmentation fault when handling untrusted GGUF files. In versions prior to 0.29.4, the function mlx::core::load_gguf() dereferences an unvalidated pointer from the external gguflib library, leading to potential application crashes. Users are encouraged to upgrade to version 0.29.4 or later to mitigate this issue.

Affected Version(s)

mlx < 0.29.4

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62609 : Segmentation Fault Vulnerability in MLX Machine Learning Framework by Apple