{"id":"CVE-2023-24832","details":"A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Hermes runtime where the EnableHermesInternal config option was set to true. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.","modified":"2026-08-18T16:23:11.983634Z","published":"2023-05-18T21:24:01.747Z","database_specific":{"cna_assigner":"facebook","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24832.json","unresolved_ranges":[{"extracted_events":[{"fixed":"5cae9f72975cf0e5a62b27fdd8b01f103e198708"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24832.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24832"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2023-24832"},{"type":"FIX","url":"https://github.com/facebook/hermes/commit/5cae9f72975cf0e5a62b27fdd8b01f103e198708"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/hermes","events":[{"introduced":"0"},{"fixed":"5cae9f72975cf0e5a62b27fdd8b01f103e198708"}],"database_specific":{"source":"REFERENCES"}}],"versions":["hermes-2022-11-03-RNv0.71.0-85613e1f9d1216f2cce7e54604be46057092939d","v0.12.0","hermes-2022-07-15-RNv0.70.0-88dd5731a19ab6b38b0a0a2d4386ba959f2a2c98","hermes-2022-04-28-RNv0.69.0-15d07c2edd29a4ea0b8f15ab0588a0c1adb1200f","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.1","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-24832.json","vanir_signatures_modified":"2026-08-18T16:23:11Z","vanir_signatures":[{"digest":{"function_hash":"310813350096616876185533241024128900640","length":2965},"id":"CVE-2023-24832-37aa9919","signature_type":"Function","signature_version":"v1","source":"https://github.com/facebook/hermes/commit/5cae9f72975cf0e5a62b27fdd8b01f103e198708","target":{"file":"lib/VM/JSLib/HermesInternal.cpp","function":"createHermesInternalObject"},"deprecated":false},{"source":"https://github.com/facebook/hermes/commit/5cae9f72975cf0e5a62b27fdd8b01f103e198708","target":{"file":"include/hermes/BCGen/HBC/BytecodeProviderFromSrc.h"},"deprecated":false,"digest":{"line_hashes":["253841271790502571321810856198638339746","188375831067382333789458430763612894097","327199981396632003971098534947807139762","318150742683929612593377450516955071494","298255200231623195542185403424602012459","244262370485217511591878998138443599837","162793595910460313883955552659308727883","211017196906887257539761348129590111588","85183650382780295955086158518426711310","120234280986884868852575566475423402228","83841357484955961474373130824488296456","339555626463210044216626526150291960724","130789605573009508699550226539158618661","21548833682316469118107994271965056098","231848456294969491461721536224423230703","279691671282868651617848889552295103287","125599540269687506273221551409803914776","251613783283780997959411931743371994186"],"threshold":0.9},"id":"CVE-2023-24832-402d2351","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2023-24832-b87103d3","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/hermes/commit/5cae9f72975cf0e5a62b27fdd8b01f103e198708","target":{"file":"lib/VM/JSLib/HermesInternal.cpp"},"deprecated":false,"digest":{"line_hashes":["71571173599479127234612705406477112512","232650399721679361189583654940619050644","192791607083652959561270852484356573359","253662568204502798766376691096096599725","93020934866911751841956221122972194389","160740943907399550141695279922793275691","233829450171247499426533330033295019655","134282450028831004591140621905749442290","258694052215063291338764337732269599047","243639082665753115833165491849669441151","119185260330026298157016928827619595933","39094233279555602251118808809054072651","318429873248738237247880592735663436281","96232456796745042778015274715874938784","18168131282844069259851179451000744194","55850491950943821989301962571113110814","277310583876919977572040881807376896452","300343611694088111301501718832858135384"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}