Stats
- First seen
- December 2023
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2018-8279, a type confusion in Microsoft Edge's parseFloat handling that can allow code execution. The rule matches the bound parseFloat invocation inside asynchronous functions that public exploits use to confuse the engine's number handling.