
Cloud Vulnerability DB
A community-led vulnerabilities database
A stack overflow vulnerability was identified in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. This vulnerability affects applications that use Hermes to execute untrusted JavaScript code (CVE Details).
The vulnerability stems from a missing check for stack overflow in the Hermes JavaScript engine's builtin apply functionality. The issue was fixed by adding a stack overflow check in the hermesBuiltinApply function (Hermes Commit).
If exploited, this vulnerability could potentially allow attackers to execute arbitrary code via crafted JavaScript. However, this is only exploitable in cases where Hermes is used to execute untrusted JavaScript, meaning most React Native applications are not affected (CVE Details).
The vulnerability was patched in commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2. Users should update to a version of Hermes that includes this fix. Additionally, applications should avoid executing untrusted JavaScript code when possible (Hermes Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."