CVE-2015-2419 is a double free vulnerability in jscript9’s native JSON APIs
Angler added new obfuscation to the exploit. The landing page fetches a stub of keys and data necessary to run the exploit from the server each time it executes.
Browser checks - the stub of information is sent only to vulnerable browsers and is protected with XTEA over modified Diffie-Hellman exchange.