flawopen.com/インシデント/BlueMoonゼロデイ多段攻撃:Chrome V8 RCEとWindows ALPC特権昇格

BlueMoonゼロデイ多段攻撃:Chrome V8 RCEとWindows ALPC特権昇格

緊急 · CVSS 9.8 CWE-787 / CWE-122: メモリ破壊攻撃チェーン エクスプロイト分析 · 2026年9月
ELI5 (5歳児でもわかる解説)

銀行の窓口を想像してください。窓口係は頑丈な防弾ガラス(Chromeサンドボックス)の向こう側に隔離されており、金庫の鍵は持っていません。攻撃者は細工した書類を使って窓口係を騙し、窓口の中を乗っ取りました(Chrome V8 RCE)。しかし防弾ガラスに阻まれて外には出られません。そこで攻撃者は、窓口と地下の管理室を繋ぐ連絡用エアシューター(Windows ALPC)に目を付け、規格外の巨大なシリンダーを無理やり送り込んで地下設備を物理的に破損させ、ビル全体のマスターキーを内部から強制解除させました(SYSTEM権限奪取)。

このページの重要用語
多段攻撃チェーン (Full-Chain Exploit)
権限のないサンドボックス環境からの遠隔コード実行(RCE)とOSカーネル特権昇格(LPE)を組み合わせ、完全なシステム乗っ取りを達成する一連の攻撃手法。
JIT投機的境界チェックの省略
JavaScriptエンジンが静的解析で「配列インデックスが絶対に上限を超えない」と判定した場合にチェックを省く高速化手法。判定ロジックのバグが境界外書き込みを生みます。
ALPC (高度ローカルプロシージャコール)
Windowsカーネルが提供するプロセス間通信機構。サンドボックス内のプロセスがOSサービスと通信する際に使用されます。
低整合性レベルとAppContainer
ファイルやレジストリへのアクセス権を極限まで削ぎ落とし、レンダラープロセスを隔離するWindowsのセキュリティ保護機構。

インシデントの概要

In early September 2026, cybersecurity researchers and threat intelligence teams discovered a sophisticated, actively exploited zero-day attack campaign dubbed 'BlueMoon'. The threat actors deployed a zero-click/one-click exploit chain targeting fully updated installations of Google Chrome on Microsoft Windows.

The attack chained two zero-days patched within days of each other:

  1. Google Chrome V8 Engine (CVE-2026-87491): An out-of-bounds memory write flaw in V8's Turbofan JIT compiler, patched on 8 September 2026 in Chrome version 153.0.8010.36/.37.
  2. Microsoft Windows Kernel ALPC Subsystem (CVE-2026-85880): A kernel pool heap overflow in the Advanced Local Procedure Call subsystem, patched by Microsoft on September 2026 Patch Tuesday.

This incident is a textbook illustration of modern systems exploitation. Because Chromium enforces rigorous process sandboxing—locking renderer processes in low-integrity AppContainers with restricted system call tables—compromising the browser engine alone was insufficient for the attackers to steal files or persist on the victim's machine. To escape containment, the attackers weaponized the ALPC subsystem exposed to the sandboxed renderer, compromising the Windows NT kernel and achieving unconstrained NT AUTHORITY\SYSTEM privileges.

多段キルチェーンと根本原因の徹底解剖

Stage 1: V8 Turbofan Speculative Optimization Failure (CVE-2026-87491)

In V8's JIT optimization pipeline, the compiler optimizes array operations by calculating integer range bounds. Due to an arithmetic truncation bug in Turbofan's Typer phase when folding 64-bit integer bitwise operations, the engine erroneously concluded that an array index could never exceed array.length. It eliminated runtime bounds checks, allowing a crafted JavaScript loop to write arbitrary pointers past the end of the backing store on the V8 heap.

Stage 2: The Chrome Sandbox Wall

Once remote code execution was achieved inside the renderer process, the attacker encountered Chrome's defense-in-depth perimeter: Win32k system calls were blocked, direct disk writes were denied by Windows Mandatory Integrity Control (Low Integrity), and outbound raw socket creation was prohibited. The attacker could not run cmd.exe or persist.

Stage 3: Windows Kernel ALPC Pool Overflow (CVE-2026-85880)

To escape the sandbox, the attacker leveraged the fact that sandboxed renderers must still communicate with system IPC endpoints via ALPC. The attacker sent an intricately malformed ALPC message structure with mismatched message length headers. In ntoskrnl.exe, the message handling routine allocated a kernel pool buffer based on the declared data size, but copied data based on the total message length, triggering an out-of-bounds heap write into the adjacent Paged Pool. The attacker corrupted an adjacent security token object to grant themselves SeDebugPrivilege and SYSTEM credentials.

脆弱な実装 vs 多層防御アーキテクチャ

VULNERABLE: TURBOFAN RANGE INFERENCE & ALPC BUFFER COPY
// 1. Conceptual V8 Turbofan Typer Flaw (CVE-2026-87491)
Type Typer::Visitor::TypeSpeculativeNumberBitwiseOr(Node* node) {
  // Bug: Underflow/truncation in 64-bit range inference
  // Compiler statically infers range [0, 10], but runtime value can reach 0x7FFFFFFF!
  return Type::Range(min_val, max_val, zone()); 
}

// 2. Conceptual Windows Kernel ALPC Heap Copy Flaw (CVE-2026-85880)
NTSTATUS AlpcpCopyMessageData(PALPC_MESSAGE Msg, PVOID Buffer) {
  // Bug: Buffer allocated from declared DataLength, but copy uses TotalLength
  ULONG allocSize = Msg->Header.u1.s1.DataLength;
  PVOID poolBlock = ExAllocatePoolWithTag(PagedPool, allocSize, 'CplA');
  
  // HEAP OVERFLOW: TotalLength > DataLength overwrites adjacent pool memory!
  RtlCopyMemory(poolBlock, Msg->PortMessage.Data, Msg->Header.u1.s1.TotalLength);
  return STATUS_SUCCESS;
}
HARDENED: CLAMPED RANGE ASSERTION & SIZE VALIDATION
// 1. Fixed V8 Turbofan Bounds Validation
Type Typer::Visitor::TypeSpeculativeNumberBitwiseOr(Node* node) {
  // Fix: Strict conservative bounding preventing speculative check elimination
  if (!IsSafeIntegerRange(min_val, max_val)) return Type::Any();
  return Type::Range(SafeClamp(min_val), SafeClamp(max_val), zone());
}

// 2. Fixed Windows Kernel ALPC Size Verification
NTSTATUS AlpcpCopyMessageData(PALPC_MESSAGE Msg, PVOID Buffer) {
  // Fix: Explicit sanity check validating header length consistency
  if (Msg->Header.u1.s1.TotalLength < Msg->Header.u1.s1.DataLength) {
    return STATUS_INVALID_PARAMETER;
  }
  // Allocate buffer matching the actual copy length, strictly bounded
  PVOID poolBlock = ExAllocatePoolWithTag(PagedPool, Msg->Header.u1.s1.TotalLength, 'CplA');
  if (!poolBlock) return STATUS_INSUFFICIENT_RESOURCES;
  RtlCopyMemory(poolBlock, Msg->PortMessage.Data, Msg->Header.u1.s1.TotalLength);
  return STATUS_SUCCESS;
}

検知およびエンドポイント監査ルール

# Sysmon Event ID 1: Detect suspicious child processes spawned from chrome.exe EventID=1 AND ParentImage="*\chrome.exe" AND Image IN ("*\cmd.exe", "*\powershell.exe", "*\whoami.exe") # ETW: Microsoft-Windows-Kernel-Memory: Monitor NonPaged/Paged Pool ALPC corruption logman start AlpcPoolTrace -p "Microsoft-Windows-Kernel-Memory" 0x80 -ets # Yara: Rule targeting the BlueMoon V8 JIT shellcode loader stage rule BlueMoon_V8_Stage1 { strings: $c = { 48 8B 04 24 48 83 C0 ?? 48 89 04 24 } condition: $c }
Enable Windows Exploit Guard and Virtualization-Based Security (VBS) with Kernel DMA Protection to stop arbitrary kernel token overwrite techniques.

システム開発者の教訓と再発防止チェックリスト

情報源および公式アドバイザリ