Logic Vulnerability in Facebook Hermes JavaScript Engine
CVE-2020-1914
9.8CRITICAL
What is CVE-2020-1914?
A logic vulnerability present in the Facebook Hermes JavaScript engine allows for potential out-of-bounds read or the execution of arbitrary code. This issue arises when processing the SaveGeneratorLong instruction. The vulnerability is particularly relevant in scenarios where applications permit evaluation of untrusted JavaScript, making it crucial for developers to be aware of its implications, especially when building with React Native frameworks.
Affected Version(s)
Hermes commit prior to b2021df620824627f5a8c96615edbd1eb7fdddfc