Junglewise Threat Intelligence

CVE-2020-1915: Meta Hermes out-of-bounds read in JavaScript interpreter

CVE-2020-1915 · Severity: low · CVSS 3.1 · Published 2022-05-24

Technologies: hermes-engine (npm), Meta Hermes. Vendors: npm, Meta.

Executive brief

Facebook Hermes is a lightweight JavaScript engine used in React Native applications. An out-of-bounds memory read in the interpreter allows an attacker to crash the application or corrupt memory by executing specially crafted JavaScript code. This vulnerability only affects applications that permit evaluation of untrusted JavaScript; most standard React Native apps are not impacted.

Technical details

An out-of-bounds read (CWE-125) exists in the JavaScript interpreter component of Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0. An attacker can trigger this vulnerability by providing crafted JavaScript code to an application that evaluates untrusted code. The vulnerability allows denial of service via interpreter crash and potential information disclosure through out-of-bounds memory reads. The vulnerability is network-reachable if the affected application accepts remote code execution, though no user interaction is required. A fix was released in Hermes 0.7.2 and later.

Affected products

  • Meta Hermes prior to 0.7.2

Timeline

  • 2020-10-26: disclosed
  • 2020-09-29: patched: Fix included in v0.7.2

References

Related threats