CVE-2023-25933 is a critical type confusion vulnerability (CWE-843) in TypedArray within Facebook Hermes, allowing for arbitrary code execution via untrusted JavaScript. With a CVSS score of 9.8, it presents a severe risk (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), though it primarily affects applications executing untrusted JavaScript with Hermes, not most React Native apps. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:facebook:hermes:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.