feedzop-word-mark-logo
searchLogin
Feedzop
homeFor YouIndiaIndia
You
bookmarksYour BookmarkshashtagYour Topics
Trending
Terms of UsePrivacy PolicyAboutJobsPartner With Us

© 2026 Advergame Technologies Pvt. Ltd. ("ATPL"). Gamezop ® & Quizzop ® are registered trademarks of ATPL.

Gamezop is a plug-and-play gaming platform that any app or website can integrate to bring casual gaming for its users. Gamezop also operates Quizzop, a quizzing platform, that digital products can add as a trivia section.

Over 5,000 products from more than 70 countries have integrated Gamezop and Quizzop. These include Amazon, Samsung Internet, Snap, Tata Play, AccuWeather, Paytm, Gulf News, and Branch.

Games and trivia increase user engagement significantly within all kinds of apps and websites, besides opening a new stream of advertising revenue. Gamezop and Quizzop take 30 minutes to integrate and can be used for free: both by the products integrating them and end users

Increase ad revenue and engagement on your app / website with games, quizzes, astrology, and cricket content. Visit: business.gamezop.com

Property Code: 5571

Home / Technology / AI Tools' Hidden Code Execution Risk Found

AI Tools' Hidden Code Execution Risk Found

14 Jan

•

Summary

  • Vulnerabilities in AI libraries allowed arbitrary code execution.
  • Apple, Salesforce, and NVIDIA libraries were affected.
  • All identified vulnerabilities were fixed by July 2025.
AI Tools' Hidden Code Execution Risk Found

Security researchers uncovered significant vulnerabilities in widely-used AI and machine learning tools, potentially allowing attackers to execute arbitrary code remotely. The flaws were discovered in three open-source Python libraries—NeMo, Uni2TS, and FlexTok—developed by Apple, Salesforce, and NVIDIA. These libraries, boasting over 10 million downloads on HuggingFace, used metadata to configure complex models, inadvertently executing any embedded code when loading modified models.

Notifications were sent to the developers in April 2025, and fixes were implemented by the end of July 2025. NVIDIA addressed CVE-2025-23304 with a high severity rating (7.8/10) in NeMo 2.3.2. FlexTok updated its code in June 2025, while Salesforce released CVE-2026-22584, a critical vulnerability (9.8/10), which was fixed in July 2025.

As of December 2025, there is no indication that these vulnerabilities have been exploited in active attacks. The discoveries were made using Palo Alto Networks' Prisma AIRS tool, highlighting the ongoing need for vigilance in AI security.

trending

Army vehicle plunges in Doda

trending

Nurses infected with Nipah virus

trending

SIDBI gets ₹5,000 cr boost

trending

FSSAI enforcement has limited impact

trending

IIFL shares plunge after tax

trending

Hang Seng Index rises

trending

Delhi weather: Yellow alert issued

trending

AFCAT 1 admit card released

trending

Gold, silver prices fall

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.
These are vulnerabilities found in AI libraries that could allow arbitrary code execution via malicious model metadata.
Yes, all three developers released fixes for the identified vulnerabilities by July 2025.
As of December 2025, there is no evidence of these vulnerabilities being exploited in the wild.

Read more news on

Technologyside-arrowApple TV+side-arrowArtificial Intelligence (AI)side-arrow

You may also like

OpenAI Secures $10B+ Compute Deal with Cerebras

15 Jan • 48 reads

article image

Big Tech's AI Feast: Startups Become Acquisition Targets

8 Jan • 126 reads

article image

Musk's xAI Raises $20B, Eyes AI Supremacy

7 Jan • 109 reads

article image

Space Data Centers: AI's Next Frontier?

1 Jan • 154 reads

article image

AI's Circular Money Machine: A Bubble in the Making?

24 Dec, 2025 • 158 reads

article image