Netskope Threat Labs

FILE-OTHER Apple Safari Type 1 fonts RCE attempt

IPS-CFWIPS-SWG

1 SID: 58524

Detects web content exploiting CVE-2020-27930, memory corruption in Safari's Type 1 font handling that can allow code execution. The rule matches the encrypted font segments that public exploits use to corrupt the font parser.