CVE-2022-27810
7.5HIGHIt was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (wh
Published: 10/6/2022Updated: 11/21/2024
Description
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.
AI AnalysisPowered by AI
Affected Products
facebookhermes
References
- https://www.facebook.com/security/advisories/cve-2022-27810Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2022-27810Third Party Advisory