Netskope Threat Labs

BROWSER-CHROME Google Chrome InspectorSession use-after-free attempt

IPS-CFWIPS-SWG

1 SID: 152020

Detects web content that exploits CVE-2024-3168, a use-after-free in Chrome's DevTools inspector session that can allow remote code execution. The rule matches the OffscreenCanvas blob conversion, worker creation, and URL manipulation sequence that public exploits use.