PYPI · AUGUST 2025 · EARLY WARNING

ExecuTorch Integer Overflow Vulnerability: Early Warning for Users

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
executorch (pypi)
Affected versions
<= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0
Patched version
Not yet available
GHSA-HJ95-MHGF-JXC4

An integer overflow vulnerability in ExecuTorch may lead to code execution. Users of affected versions should assess their exposure and apply recommended mitigations.

What happened

An integer overflow vulnerability has been reported in ExecuTorch, a software component used for loading models. This vulnerability, tracked as GHSA-HJ95-MHGF-JXC4, can result in overlapping memory allocations, which may allow an attacker to execute arbitrary code or cause other undesirable effects. The issue affects versions prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.

The vulnerability impacts multiple components and version ranges within the ExecuTorch ecosystem. Users are advised to review the affected version ranges and determine if their installations are vulnerable. The primary sources indicate that no exploitation in the wild has been confirmed at this time.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If executorch is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using executorch (pypi) versions <= 0.6.0 or < 0.7.0, org.pytorch:executorch-android (maven) versions < 0.7.0, or github.com/pytorch/executorch (swift) versions < 0.7.0.

What should I do right now?

Upgrade executorch to commit d158236b1dc84539c1b16843bc74054c9dcba006 or later. Check your installations against the affected version ranges and monitor the primary sources for updates.

Is there an official fix available?

Yes, upgrading to commit d158236b1dc84539c1b16843bc74054c9dcba006 or later is recommended to mitigate the vulnerability.

Sources

Join the 0Day waitlist →

← Back to all threats