CVE-2026-35502: Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Appli
Summary
Intel's Extension for PyTorch before version 2.8.0 has a vulnerability involving deserialization of untrusted data (processing data from unverified sources without proper validation), which could allow a local user to gain higher privileges on a system. An attacker would need local access and the user to interact with the software, but the actual security impact on the system is expected to be low.
Solution / Mitigation
Update Intel(R) Extension for PyTorch to version 2.8.0 or later.
Vulnerability Details
EPSS: 0.0%
August 11, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-35502
First tracked: August 11, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 85%