Netskope Threat Labs

BROWSER-CHROME Google Chrome PNG in TTF parsing heap overflow attempt

IPS-CFWIPS-SWG

5 SIDs: 56130, 200076, 200077, 200078, 200223

First seen
January 2022
Last seen
October 2026

Detects web content that exploits CVE-2020-15999, a heap buffer overflow when Chrome's FreeType library parses a PNG image embedded in a TrueType font, which can allow remote code execution. The rule matches the FontFace API loading a font with an embedded PNG, and Google confirmed exploitation in the wild before the November 2020 patch.