CVE-2020-1914 is a critical logic vulnerability in Facebook Hermes (prior to commit b2021df620824627f5a8c96615edbd1eb7fdddfc) that could allow attackers to read out-of-bounds memory or theoretically execute arbitrary code through crafted JavaScript. This vulnerability is rated 9.8 (CRITICAL) on the CVSS scale, indicating a severe risk with network accessibility and no user interaction required for exploitation. However, it is only exploitable if the application using Hermes allows evaluation of untrusted JavaScript, meaning most React Native applications are not affected. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020-10-01CPE matchmatch criteria | cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.