Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer BooleanProtoObj objects JSONStringifyArray use-after-free attempt

IPS-SWG

1 SID: 38828

First seen
January 2023
Last seen
August 2025

Detects web content that exploits CVE-2016-0187, a use-after-free in Internet Explorer's JSON serialization that can allow code execution. The rule matches the deletion during stringification that public exploits use to free objects while the serializer still references them.