BleepingComputer says multiple cyber-espionage groups are using the BlueMoon exploit kit to chain two Google Chrome V8 sandbox escapes, CVE-2026-85046 and CVE-2026-87491, with a Windows ALPC local privilege escalation, CVE-2026-85880. The result is not a browser crash or a tab breakout; it is a path from one malicious page to full control of a Windows machine.
BlueMoon first gets code running inside Chrome’s sandbox, then uses the Windows flaw to jump out of the browser and reach system level. That means the browser boundary is only a foothold, not containment, when the paired Windows bug is still present.
For Windows fleets, the exposure sits at the endpoint layer even if Chrome is updated. If the Windows privilege-escalation path remains open, a page delivered through the browser can still end in machine takeover.