Netskope Threat Labs

BROWSER-FIREFOX Mozilla Firefox javascript type confusion code execution attempt

IPS-CFWIPS-SWG

2 SIDs: 48564, 200319

First seen
December 2023
Last seen
October 2026

Detects JavaScript that exploits CVE-2018-12386, a type confusion in Firefox's JavaScript engine that can allow code execution. The rule matches the cyclic object property pattern that public exploits use to confuse the engine's handling of nested values, then groom memory through warmup loops.