Type Confusion Vulnerability in Hermes JavaScript Engine by Facebook
CVE-2023-25933

9.8CRITICAL

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
18 May 2023

What is CVE-2023-25933?

A type confusion vulnerability exists in the Hermes JavaScript engine, impacting versions prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81. This issue could potentially be exploited by attackers to execute arbitrary code through untrusted JavaScript, particularly when the engine is utilized in an environment that processes untrusted inputs. However, it's important to note that this vulnerability primarily affects applications using Hermes for executing such scripts.

Affected Version(s)

Hermes 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.