CVE-2023-28081
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.
| Vendor | |
| Product | hermes |
| Published | May 18, 2023 |
| Last Updated | Jan 21, 2025 |
Stay Ahead of the Next One
Get instant alerts for facebook hermes
Be the first to know when new critical vulnerabilities affecting facebook hermes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Facebook / Hermes
0 < e6ed9c1a4b02dc219de1648f44cd808a56171b81