Netskope Threat Labs

BROWSER-CHROME Google Chrome ScriptProcessorNode race condition exploit attempt

IPS-SWG

1 SID: 58683

Detects web content that exploits CVE-2021-21166, an object lifecycle race in Chrome's audio processing that can allow remote code execution. The rule matches the ScriptProcessorNode and buffer manipulation that public exploits use to win the race between the audio and main threads, and Google confirmed exploitation in the wild.