Netskope Threat Labs

BROWSER-IE Microsoft Edge parseFloat type confusion attempt

IPS-CFWIPS-SWG

1 SID: 47098

First seen
December 2023
Last seen
October 2026

Detects web content that exploits CVE-2018-8279, a type confusion in Microsoft Edge's parseFloat handling that can allow code execution. The rule matches the bound parseFloat invocation inside asynchronous functions that public exploits use to confuse the engine's number handling.