First published: Tue Oct 11 2022(Updated: )
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook Hermes | <0.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35289 is a vulnerability in Hermes, a JavaScript engine developed by Facebook, that allows attackers to potentially execute arbitrary code via crafted JavaScript.
The severity of CVE-2022-35289 is critical, with a CVSS score of 9.8.
Hermes versions up to and excluding 0.12.0 are affected by CVE-2022-35289.
To fix CVE-2022-35289, it is recommended to update Hermes to a version beyond 0.12.0, which includes the fix for the vulnerability.
You can find more information about CVE-2022-35289 in the official Facebook Security Advisories and the GitHub commit linked in the references.