Type Confusion Vulnerability in Hermes JavaScript Engine by Facebook
CVE-2023-25933
9.8CRITICAL
What is CVE-2023-25933?
A type confusion vulnerability exists in the Hermes JavaScript engine, impacting versions prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81. This issue could potentially be exploited by attackers to execute arbitrary code through untrusted JavaScript, particularly when the engine is utilized in an environment that processes untrusted inputs. However, it's important to note that this vulnerability primarily affects applications using Hermes for executing such scripts.
Affected Version(s)
Hermes 0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved