Netskope Threat Labs

BROWSER-CHROME Google Chrome Animation timeline use after free attempt

IPS-SWG

1 SID: 60362

First seen
November 2023
Last seen
September 2026

Detects web content that exploits CVE-2022-0609, a use-after-free in Chrome's animation timeline implementation that can allow remote code execution. The rule matches the DocumentTimeline and animation callbacks from public exploits, and the Google Threat Analysis Group documented use of this vulnerability in targeted attacks attributed to North Korean actors.