Stats
- First seen
- January 2022
- Last seen
- September 2025
Description
Detects JavaScript that exploits CVE-2019-11707, a type confusion in Firefox's handling of Array.prototype.pop that can allow code execution. The rule matches the pattern of removing array elements while reassigning their prototype, which confuses the engine's array bookkeeping and corrupts memory.