Junglewise Threat Intelligence

CVE-2025-54950: PyTorch ExecuTorch out-of-bounds read in model loading

CVE-2025-54950 · Severity: critical · CVSS 9.8 · Published 2025-08-08

Technologies: executorch (PyPI), github.com/pytorch/executorch (Swift), org.pytorch:executorch-android (Maven). Vendors: PyTorch, PyPI, Swift, Maven.

Executive brief

ExecuTorch is PyTorch's runtime for executing machine learning models on mobile and edge devices. A flaw in how ExecuTorch loads model files allows attackers to craft malicious models that read memory beyond intended boundaries. This can crash the application, leak sensitive data from memory, or enable attackers to execute arbitrary code on the affected device.

Technical details

The vulnerability is a classic CWE-125 out-of-bounds read occurring during model deserialization/loading. The root cause stems from insufficient bounds checking in generated kernel code—specifically in primitive operators like `et_copy_index` that manipulate tensor stacks. An attacker can construct a malformed ExecuTorch model file that, when loaded, violates expected stack size assumptions, causing the runtime to read past buffer boundaries. The attack is network-accessible (remote model loading), requires no privileges or user interaction, and impacts confidentiality, integrity, and availability. The fix (commit fb03b6f and b6b7a16) adds safety checks via `ET_KERNEL_CHECK_MSG` macros to validate stack sizes before access. Patched version 0.7.0 is available.

Affected products

  • PyTorch ExecuTorch < 0.7.0
  • PyTorch ExecuTorch Android < 0.7.0

Timeline

  • 2025-08-07: disclosed: Published to National Vulnerability Database
  • 2025-08-08: disclosed: Published to GitHub Advisory Database
  • 2025-07-29: patched: Safety checks added to prim kernels (commit b6b7a16)
  • 2025-08-01: patched: Safety checks added to generated kernels (commit fb03b6f); version 0.7.0 released

References

Related threats