Netskope Threat Labs

BROWSER-CHROME Google Chrome Updater privilege escalation attempt via malicious file

IPS-CFWIPS-SWG

2 SIDs: 152023, 152024

Detects code that manipulates the Keystone registration archive and update daemon files on macOS, tied to CVE-2024-3173, an elevation of privilege vulnerability in Chrome's updater that can grant elevated system permissions through a malicious file.