A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a proto property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serializable.native.ts. When affected data is subsequently processed by React Native Worklets, the malformed serialized object can cause the React Native application to crash. This can result in a remotely triggered denial of service in applications that pass attacker-controlled data through the affected serialization path. In applications where the attacker-controlled data is persisted, the denial of service may persist across application restarts or repeated attempts to access the affected content.
An application must pass attacker-controlled object data containing a "proto" property through the affected React Native Worklets serialization path.
Applications can recursively reject or remove prototype-sensitive properties such as "proto", "constructor", and "prototype" from untrusted objects before passing them to affected Worklets APIs.
Upgrade React Native Worklets to version 0.12.2 or later. Version 0.12.2 includes the upstream fix for unsafe handling of "proto" properties during serialization and deserialization.