Netskope Threat Labs

BROWSER-IE Google Chrome LinkToTextMenuObserver heap use-after-free attempt

IPS-SWG

1 SID: 60918

First seen
April 2023
Last seen
September 2023

Detects web content that exploits CVE-2022-2998, a heap use-after-free in Google Chrome's link-to-text context menu handling that can allow code execution. The rule matches a cross-frame sequence that selects text, opens the context menu, and frees the menu observer while it remains in use.