Stats
- First seen
- March 2026
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2026-2441, a memory corruption vulnerability involving the CSSFontFeatureValuesMap interface that can allow remote code execution. The rule matches style sheets that declare font feature values and then mutate the map's entries while the engine iterates over them.