Description
Detects web content that exploits incorrect side-effect modeling of the `in` operator in Apple Safari's JavaScript engine, covered by CVE-2020-9801, CVE-2020-9850, and CVE-2020-9856, which can allow code execution. The rule matches float array grooming and a DOM mutation event trigger that public exploits use to confuse the optimizing compiler.