Skip to finding
§
High
Browser to host
Confirmed
CVE-2026-85046

BlueMoon turns one clicked Chrome link into attacker-chosen execution outside the renderer sandbox.

Proofpoint recovered deployed samples associated with four espionage clusters.

Affects

Google Chrome on Microsoft Windows desktops and servers targeted by the BlueMoon espionage exploit kit.

What it enables

Web-delivered command execution outside the Chrome renderer sandbox

Deliver a link to a BlueMoon-controlled page and induce the recipient to open it in affected Chrome.→↓Exploit CVE-2026-85046 to obtain address disclosure, fake-object construction and arbitrary read/write inside the V8 heap cage.→↓Exploit CVE-2026-87491 to replace WebAssembly compiled-function bodies with attacker shellcode and escape the V8 sandbox.→↓Exploit CVE-2026-85880 through Windows ALPC/WNF to obtain kernel read/write and enable SeDebugPrivilege in the renderer token.→↓Inject a CreateProcess stub into Chrome’s broker process, download an operator-selected executable and run it outside the renderer sandbox.
Why this matters

What changed is composition and use: three primitives now form an observed click-to-broker execution chain.

Detail and 2 sources
Required access

Internet delivery of a malicious link followed by the recipient opening it in affected Chrome on Windows

Affected versions

Chrome before 152.0.7977.82/.83 for CVE-2026-85046, Chrome before 153.0.8010.36/.37 for CVE-2026-87491, Windows builds 17763, 19041–19045, 20348 and 22000 in the observed BlueMoon chain

After the recipient opens a link in affected Chrome on Windows, the chain uses V8 read/write, replaces WebAssembly code and then uses an ALPC/WNF kernel exploit.

The final stage enables SeDebugPrivilege, injects into Chrome’s broker and runs an operator-selected executable outside the renderer sandbox.

Google confirms that Chrome 153 fixes CVE-2026-87491. The operational evidence makes stale affected Windows browser builds an immediate update target.

Evidence
Proofpoint recovered and analyzed deployed exploit-kit samples from four actor clusters and documented each chain primitive and final payload execution path.Google’s stable-channel notice confirms the CVE-2026-87491 fix and Chrome 153 versions.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026