BlueMoon Exploit Kit Can Escape Chrome and Elevate Windows Privileges


chrome vulnerability chain
Image credit: Google

BlueMoon exploit kit chains Windows and Chrome zero-days in targeted attacks, giving cyber-espionage groups a way to execute code, escape Chrome’s sandbox, and gain elevated Windows privileges.

Proofpoint observed attacks involving BlueMoon starting on August 28, 2026, while Volexity tracked similar activity from September 1.

Researchers describe BlueMoon as a modular exploit framework that multiple threat actors can share and update with additional vulnerabilities.

BlueMoon chains three Chrome and Windows vulnerabilities

The exploit chain relies on three vulnerabilities affecting Google Chrome and Microsoft Windows.

CVE-2026-85046 is a type-confusion vulnerability in Chrome’s V8 JavaScript engine that allows arbitrary memory access inside the V8 sandbox. Google confirmed active exploitation of the Chrome zero-day and has already released a fix.

BlueMoon then uses CVE-2026-87491 to escape the V8 sandbox by corrupting WebAssembly metadata and executing embedded shellcode. Google fixed the vulnerability alongside 230 other Chrome security flaws in a recent update.

The final stage uses CVE-2026-85880, a heap-based buffer overflow in Windows ALPC that enables local privilege escalation. Microsoft addressed the flaw in its latest September 2026 Patch Tuesday updates.

Proofpoint believes attackers exploited CVE-2026-85880 as a zero-day and may have used it in attacks dating back to 2025.

How the BlueMoon exploit chain works

BlueMoon starts the exploitation process inside a Web Worker and can retry the attack up to five times if an attempt fails.

After compromising the Chrome renderer, the kit uses the Windows ALPC vulnerability to increase its privileges. It then injects code into Chrome’s parent process.

From there, BlueMoon uses curl to download a malware loader into the %TEMP% directory and execute it on the compromised Windows system.

Attackers exploit the Chromium patch gap

Researchers also highlighted how BlueMoon developers take advantage of the delay between public Chromium security fixes and their arrival in stable Chrome releases.

Once Chromium developers publish security-related code changes, attackers can reverse-engineer those changes and identify the underlying vulnerability before every user receives the stable browser update.

That window gives exploit developers time to build attacks against systems that remain unpatched.

Multiple threat groups are already using BlueMoon

Researchers identified four separate activity clusters deploying BlueMoon.

Three of those clusters involve Chinese or China-aligned threat actors, suggesting the exploit kit has already spread across multiple cyber-espionage operations rather than remaining exclusive to a single group.

Proofpoint expects BlueMoon adoption to grow further and warns that financially motivated cybercriminals could eventually gain access to the framework.

Both Proofpoint and Volexity have published indicators of compromise covering malicious files and attacker-controlled infrastructure. Organizations can use those indicators to detect and block BlueMoon-related activity before attackers move deeper into their networks.

Via BleepingComputer

More about the topics: Chrome, Google, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages