CVE-2021-24037 describes a critical use-after-free vulnerability in Facebook's Hermes JavaScript engine, specifically when emitting certain error messages. This flaw, present before commit d86e185e485b6330216dee8e854455c694e3a36e, could allow attackers to execute arbitrary code through crafted JavaScript. With a CVSS score of 9.8 (CRITICAL), it presents a high-impact threat (confidentiality, integrity, availability) with a network attack vector and low attack complexity, though it primarily affects applications permitting untrusted JavaScript evaluation, largely excluding typical React Native apps. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.0CPE matchmatch criteria | cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.