CVE-2025-14569EPSS p2.6%
CVE-2025-14569CVE-2025-14569
Description
A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.14% probability of exploitation · percentile 2.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |