Stats
- First seen
- December 2023
- Last seen
- October 2026
Description
Detects JavaScript that exploits CVE-2018-12386, a type confusion in Firefox's JavaScript engine that can allow code execution. The rule matches the cyclic object property pattern that public exploits use to confuse the engine's handling of nested values, then groom memory through warmup loops.