Stats
- First seen
- December 2023
- Last seen
- October 2026
Description
Detects JavaScript that exploits CVE-2018-12387, a flaw in Firefox's handling of Array.prototype.push with user-supplied arguments that can allow code execution. The rule matches the push invocation with numeric grooming and typed array setup that public exploits use to corrupt memory.