Stats
- First seen
- February 2023
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2021-21220, incorrect integer handling in the V8 engine in Chrome that can allow remote code execution. The rule matches the Uint32Array with a 2 to the power 31 value that the publicly released exploit uses to confuse the optimizer, and Google patched the flaw in April 2021 after the exploit circulated.