BlueMoon composes a clicked browser link into Windows broker command execution.
Google Chrome and Chromium-based browsers on selected Windows 10, Windows 11 and Windows Server builds targeted by the BlueMoon exploit kit.
Two V8 flaws provide renderer execution, an ALPC/WNF exploit changes token rights, and injected broker code downloads and executes the operator-selected payload.
Detail and 5 sources
Proofpoint observed four threat clusters deploy the complete chain, and Google confirmed exploitation of the V8 components in the wild.
Today's change is evidence that the previously tracked browser bugs were operationally composed through the Windows sandbox boundary; Google and Microsoft have shipped fixes.