An error in BigInt conversion to... CVE-2023-23556

- AV AC AU C I A
发布: 2023-05-18
修订: 2023-11-07

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息