Netskope Threat Labs

BROWSER-FIREFOX Mozilla Firefox IonMonkey type confusion attempt

IPS-CFWIPS-SWG

2 SIDs: 58611, 200104

First seen
December 2023
Last seen
August 2026

Detects JavaScript that exploits CVE-2019-17026, a type confusion in Firefox's IonMonkey optimizing compiler that can allow code execution. The rule matches the defineSetter and array manipulation pattern that public exploits use to confuse the compiler's type tracking.