Netskope Threat Labs

BROWSER-CHROME Google Chrome WebRTC addIceCandidate use after free attempt

IPS-CFWIPS-SWG

1 SID: 57938

First seen
October 2023
Last seen
October 2026

Detects web content that exploits CVE-2021-30602, a use-after-free in Chrome's WebRTC session description handling that can allow remote code execution. The rule matches the local description and candidate promise chain that public exploits use to free the transport while it remains in use.