PT-2023-22710 · Hermes · Hermes

CVE-2023-30470

·

Publicado

2023-05-18

·

Atualizado

2025-01-21

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hermes versions prior to commit da8990f737ebb9d9810633502f65ed462b819c09
Description A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled could have been used by an attacker to achieve remote code execution. This issue is only exploitable in cases where Hermes is used to execute untrusted JavaScript, and most React Native applications are not affected.
Recommendations For versions prior to commit da8990f737ebb9d9810633502f65ed462b819c09, update to a version that includes the fix for the use-after-free issue in bytecode generation. As a temporary workaround, consider disabling optimizations for Hermes when executing untrusted JavaScript until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30470

Produtos afetados

Hermes