Stats
- First seen
- February 2023
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2021-21224, a type confusion in the V8 engine in Chrome that can allow remote code execution. The rule matches the Math.max call on a 32-bit unsigned value that public exploits use to confuse the optimizer, and Google confirmed exploitation in the wild before the April 2021 patch.