facebook hermes CVE-2021-24045 is a vulnerability in Facebook Hermes
Published on December 13, 2021

A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

NVD

Weakness Type

What is an Object Type Confusion Vulnerability?

The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

CVE-2021-24045 has been classified to as an Object Type Confusion vulnerability or weakness.


Products Associated with CVE-2021-24045

Want to know whenever a new CVE is published for Facebook Hermes? stack.watch will email you.

 

Affected Versions

Facebook Hermes:

Exploit Probability

EPSS
0.55%
Percentile
67.44%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.