CVE-2023-28081: Facebook Hermes

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

Affected products

  • Facebook Hermes: affected versions not specified

Published 2023-05-18. Last modified 2026-06-17.