Stats
- First seen
- July 2025
- Last seen
- September 2026
Description
Detects PDF files that exploit CVE-2024-4367, a flaw in the PDF.js viewer in Firefox ESR and Firefox that lets malformed font matrices run arbitrary JavaScript. The rule inspects email traffic for PDF documents carrying the crafted FontMatrix entry that public exploits use, and a successful exploit can lead to code execution in the viewer context.