Netskope Threat Labs

BROWSER-CHROME Google Chrome V8 JavaScript Engine type confusion attempt

IPS-SWG

1 SID: 58613

First seen
July 2024
Last seen
June 2025

Detects attempts to exploit a type confusion vulnerability in the V8 JavaScript engine in Google Chrome that can allow remote code execution. The rule inspects files transferred over the web or delivered by email for distinctive sequences in public exploits for CVE-2021-30551 and CVE-2020-6383, including JavaScript that assigns a handler to `embed.onload` and then calls `Object.setPrototypeOf()` to set the element's prototype to `null`, confusing the V8 optimizer, and corrupting memory. Google released Chrome 91.0.4472.114 to fix CVE-2021-30551 after confirming exploitation in the wild.