NVIDIA has disclosed multiple critical vulnerabilities in its Isaac Launchable product, each carrying a CVSS v3.1 base score of 9.8, indicating a severe risk to affected systems. The vulnerabilities include two privilege escalation flaws (CVE-2025-33223 and CVE-2025-33224) that allow attackers to execute code with unnecessary privileges, potentially leading to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. Additionally, a hard-coded credential vulnerability (CVE-2025-33222) could be exploited to achieve similar impacts, including unauthorized access and manipulation of system data. All vulnerabilities are remotely exploitable and require immediate attention.
NVIDIA has released security updates to address these issues and strongly recommends that users download and install the latest version of Isaac Launchable to mitigate the risks. The official security bulletin provides detailed descriptions of each CVE, their associated CWE categories, and the potential impacts. Organizations using NVIDIA Isaac Launchable should prioritize patching to prevent exploitation, as the vulnerabilities could be leveraged by remote attackers without user interaction or prior authentication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
NVIDIA PSIRT disclosed CVE-2025-33224, another critical Isaac Launchable vulnerability tied to execution with unnecessary privileges. The remotely exploitable flaw requires no user interaction and could result in code execution, privilege escalation, denial of service, information disclosure, and data tampering.
NVIDIA PSIRT disclosed CVE-2025-33223, a critical Isaac Launchable vulnerability involving execution with unnecessary privileges. The issue is remotely exploitable without prior privileges or user interaction and may lead to code execution, privilege escalation, denial of service, information disclosure, and data tampering.
NVIDIA PSIRT disclosed CVE-2025-33222, a critical hard-coded credentials vulnerability in Isaac Launchable. The flaw is remotely exploitable without authentication or user interaction and could enable code execution, privilege escalation, denial of service, information disclosure, and data tampering.
NVIDIA published Security Bulletin 5749 for Isaac Launchable, disclosing multiple critical vulnerabilities affecting the product. The bulletin serves as the vendor advisory for the issues later tracked as CVE-2025-33222, CVE-2025-33223, and CVE-2025-33224.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcenvidia.custhelp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.