Netskope Threat Labs

BROWSER-WEBKIT JavaScriptCore watchpoint type confusion attempt

IPS-SWG

1 SID: 60414

First seen
July 2024
Last seen
July 2024

Detects web content that exploits CVE-2019-8506, a type confusion in JavaScriptCore's watchpoint handling that can allow code execution. The rule matches a getter installed deep in Array.prototype that public exploits use to fire the watchpoint with mismatched types.