CVE-2023-23556: Facebook Hermes
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.
Affected products
- Facebook Hermes: before 2023-02-02 (fixed in 2023-02-02)
Published 2023-05-18. Last modified 2026-06-17.