ExecuTorch Vulnerability: Heap-based Buffer Overflow Risk
- Severity
- HIGH
- Affected component
- executorch (pypi)
- Affected versions
- <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0
- Patched version
- Not yet available
ExecuTorch is under investigation for a heap-based buffer overflow vulnerability in model loading. This issue may lead to runtime crashes and potential code execution.
What happened
ExecuTorch versions prior to commit cea9b23aa8ff78aff92829a466da97461cc7930c are reportedly vulnerable to heap-based buffer overflows when loading models. This vulnerability can cause runtime crashes and may potentially allow for code execution. The issue affects various versions of the executorch package on PyPI, org.pytorch:executorch-android on Maven, and github.com/pytorch/executorch in Swift.
The vulnerability was first flagged on August 8, 2025. It is currently under investigation and has not been reported as exploited in the wild. Users are advised to upgrade to the latest version of ExecuTorch and monitor for any runtime crashes or unexpected behavior.
What to do about it
- Upgrade to the latest version of ExecuTorch.
- Monitor your applications for any runtime crashes or unexpected behavior.
- Consult the primary sources for updates on the vulnerability and any available patches.
How 0Day would have caught this
executorch is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using versions of executorch (PyPI) prior to commit cea9b23aa8ff78aff92829a466da97461cc7930c, org.pytorch:executorch-android (Maven) versions prior to 0.7.0, or github.com/pytorch/executorch (Swift) versions prior to 0.7.0.
What should I do right now?
Upgrade to the latest version of ExecuTorch and monitor your applications for any runtime crashes or unexpected behavior.
Has an official fix been released?
No official fix has been published yet. Monitor the sources for updates.