CVE-2023-28081: Facebook Hermes
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.
Affected products
- Facebook Hermes: affected versions not specified
Published 2023-05-18. Last modified 2026-06-17.