CVE-2025-62609
21.11.2025, 19:16
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched in version 0.29.4.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ml-explore | mlx | 𝑥 < 0.29.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration