← Back to CVE List

CVE-2023-28081

Published: 2023-05-18T22:15Z
Last Modified: 2025-01-21T21:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt