Netskope Threat Labs

BROWSER-FIREFOX Firefox ESR PDF.js Arbitrary Javascript Execution (CVE-2024-4367)

IPS-CFWIPS-SWG

1 SID: 152040

First seen
July 2025
Last seen
September 2026

Detects PDF files that exploit CVE-2024-4367, a flaw in the PDF.js viewer in Firefox ESR and Firefox that lets malformed font matrices run arbitrary JavaScript. The rule inspects email traffic for PDF documents carrying the crafted FontMatrix entry that public exploits use, and a successful exploit can lead to code execution in the viewer context.