Junglewise Threat Intelligence

CVE-2020-1911: Facebook Hermes type confusion in prototype chain resolution

CVE-2020-1911 · Severity: low · CVSS 3.1 · Published 2022-05-24

Technologies: hermes-engine (npm). Vendors: npm.

Executive brief

Facebook Hermes is a JavaScript engine used in React Native applications. A type confusion vulnerability in how Hermes resolves JavaScript object properties allows attackers to execute arbitrary code if the application evaluates untrusted JavaScript code—a rare scenario that most React Native apps do not enable.

Technical details

This is a type confusion vulnerability (CWE-843) in Facebook Hermes' property resolution logic when handling JavaScript objects with specially-crafted prototype chains. The root cause is improper handling of HostObject computed properties during prototype chain lookups in the JSObject component. An attacker who can provide crafted JavaScript code to the Hermes engine can trigger arbitrary code execution. The vulnerability requires the application to permit evaluation of untrusted JavaScript—most React Native applications do not enable this capability and are therefore not affected. The fix was committed in Hermes prior to version 0.5.2; versions 0.4.3 and earlier are vulnerable.

Affected products

  • Facebook Hermes prior to 0.5.2

Timeline

  • 2020-09-04: disclosed: Published on NVD
  • 2022-05-24: advisory: GitHub advisory GHSA-f5x2-xv93-4p23 published
  • 2020: patched: Fixed in Hermes 0.5.2

References

Related threats