VDB

CVE-2025-30405

CVE-2025-30405 PUBLISHED CVSS 9.800000190734863 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 0830af8207240df8d7f35b984cdf8bc35d74fa73.

EPSS 0.60% · 47.2th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.60%
47.2th percentile

Affected Products

VendorProductVersions
PyPIexecutorch0
Meta Platforms, IncExecuTorch0
SwiftURLexecutorch0
Mavenorg.pytorch:executorch-android0

Timeline

  • Aug 7, 2025 CVE Published
  • Aug 8, 2025 EPSS Score
  • Aug 8, 2025 Coalition ESS Score
  • Aug 8, 2025 Coalition ESS Score
  • Aug 11, 2025 PoC Published
  • Aug 12, 2025 Coalition ESS Score
  • Aug 17, 2025 EPSS Score
  • Aug 22, 2025 Coalition ESS Score
  • Aug 26, 2025 EPSS Score
  • Aug 26, 2025 Coalition ESS Score
  • Sep 4, 2025 EPSS Score
  • Sep 12, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›