Metro4Shell (CVE-2025-11953): Critical React Native Metro Server Vulnerability Exploited in the Wild
The critical vulnerability CVE-2025-11953, informally dubbed Metro4Shell, is being actively abused to compromise React Native development environments. Attackers are exploiting a flaw in the Metro server — the default JavaScript bundler for React Native — to deploy malicious payloads on Windows and Linux systems directly inside developer workstations and build environments. What the React Native … Read more