An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
{ "nvd_published_at": "2020-09-09T19:15:00Z", "github_reviewed_at": "2022-06-24T01:23:39Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-195", "CWE-681" ] }