Stats
- First seen
- May 2026
- Last seen
- October 2026
Description
Detects PDF documents transferred over the web that exploit CVE-2024-4367, a flaw in the PDF.js viewer in Firefox that lets malformed font matrices run arbitrary JavaScript. The rule matches the PDF header followed by the crafted FontMatrix entry that public exploits use, and a successful exploit can lead to code execution in the viewer context.