Stats
- First seen
- January 2022
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2020-15999, a heap buffer overflow when Chrome's FreeType library parses a PNG image embedded in a TrueType font, which can allow remote code execution. The rule matches the FontFace API loading a font with an embedded PNG, and Google confirmed exploitation in the wild before the November 2020 patch.