Netskope Threat Labs

BROWSER-CHROME Google Chrome ServiceWorkerVersion use-after-free javascript file download attempt

IPS-SWG

1 SID: 62536

First seen
December 2024
Last seen
October 2026

Detects web content that exploits CVE-2022-2480 through a service worker whose install event never settles, which keeps the vulnerable object alive while a JavaScript file downloads. The rule matches the never-resolving promise pattern from public exploits.