What the vulnerability does

01Description

A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

Key dates

02Disclosure timeline

December 13, 2021 CVE published
August 3, 2024 Record updated