CVE-2023-23556 is a critical vulnerability affecting Facebook Hermes, stemming from an out-of-bounds write during BigInt to Number conversion. This flaw, present in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80, could allow a malicious attacker to execute arbitrary code when untrusted JavaScript is processed. With a CVSS score of 9.8 (CRITICAL), it boasts a low attack complexity and requires no user interaction, leading to potential high impacts on confidentiality, integrity, and availability. While not actively exploited in the wild and lacking public exploit code, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-02-02CPE matchmatch criteria | cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.