Skip to finding
important · Edge — Browser chain

BlueMoon composes a clicked browser link into Windows broker command execution.

Affects

Google Chrome and Chromium-based browsers on selected Windows 10, Windows 11 and Windows Server builds targeted by the BlueMoon exploit kit.

Two V8 flaws provide renderer execution, an ALPC/WNF exploit changes token rights, and injected broker code downloads and executes the operator-selected payload.

Detail and 5 sources

Proofpoint observed four threat clusters deploy the complete chain, and Google confirmed exploitation of the V8 components in the wild.

Today's change is evidence that the previously tracked browser bugs were operationally composed through the Windows sandbox boundary; Google and Microsoft have shipped fixes.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026