flawopen.com/安全事件/BlueMoon 完整利用链:Chrome V8 远程执行与 Windows 内核提权

BlueMoon 完整利用链:Chrome V8 远程执行与 Windows 内核提权

严重危险 · CVSS 9.8 CWE-787 / CWE-122: 堆内存破坏链 完整利用链剖析 · 2026年9月
ELI5 (通俗解释)

把整个系统想象成一座戒备森严的银行:柜台员工在防弹玻璃后办公(Chrome 渲染器沙箱),手中没有任何进入金库或控制室的钥匙。劫匪通过假支票上的光学幻觉控制了柜台(Chrome V8 漏洞执行代码)。然而劫匪被困在防弹玻璃内部无法触碰外部金库。此时,劫匪发现柜台与地下机房之间连接着一根用于传输票据的气动邮件管道(Windows 内核 ALPC 系统)。劫匪将特制的超大金属罐强行塞入管道,导致地下机房设备过载爆裂,从内部反向解锁了整座大楼的总控制权限(提权至 SYSTEM)。

核心技术概念
完整利用链 (Full-Chain Exploit)
将多个处于不同安全边界和权限层级的独立漏洞串联起来的攻击手法——通常将非特权沙箱内的远程执行漏洞与操作系统内核提权漏洞相结合。
JIT 投机性边界检查消除
JIT 编译器的一种优化机制,当推断数组索引绝不可能越界时省略运行时检查。推断逻辑出现数学计算错误便会导致堆越界读写。
高级本地过程调用 (ALPC)
Windows 内核提供的高性能进程间通信机制,非特权用户程序通过该接口请求系统服务与驱动处理。
AppContainer 与低完整性级别
Windows 操作系统的沙箱隔离机制,剥夺进程的文件读写、网络监听和注册表访问权限。

事件全景复盘

In early September 2026, cybersecurity researchers and threat intelligence teams discovered a sophisticated, actively exploited zero-day attack campaign dubbed 'BlueMoon'. The threat actors deployed a zero-click/one-click exploit chain targeting fully updated installations of Google Chrome on Microsoft Windows.

The attack chained two zero-days patched within days of each other:

  1. Google Chrome V8 Engine (CVE-2026-87491): An out-of-bounds memory write flaw in V8's Turbofan JIT compiler, patched on 8 September 2026 in Chrome version 153.0.8010.36/.37.
  2. Microsoft Windows Kernel ALPC Subsystem (CVE-2026-85880): A kernel pool heap overflow in the Advanced Local Procedure Call subsystem, patched by Microsoft on September 2026 Patch Tuesday.

This incident is a textbook illustration of modern systems exploitation. Because Chromium enforces rigorous process sandboxing—locking renderer processes in low-integrity AppContainers with restricted system call tables—compromising the browser engine alone was insufficient for the attackers to steal files or persist on the victim's machine. To escape containment, the attackers weaponized the ALPC subsystem exposed to the sandboxed renderer, compromising the Windows NT kernel and achieving unconstrained NT AUTHORITY\SYSTEM privileges.

完整攻击杀伤链与技术根本原因

Stage 1: V8 Turbofan Speculative Optimization Failure (CVE-2026-87491)

In V8's JIT optimization pipeline, the compiler optimizes array operations by calculating integer range bounds. Due to an arithmetic truncation bug in Turbofan's Typer phase when folding 64-bit integer bitwise operations, the engine erroneously concluded that an array index could never exceed array.length. It eliminated runtime bounds checks, allowing a crafted JavaScript loop to write arbitrary pointers past the end of the backing store on the V8 heap.

Stage 2: The Chrome Sandbox Wall

Once remote code execution was achieved inside the renderer process, the attacker encountered Chrome's defense-in-depth perimeter: Win32k system calls were blocked, direct disk writes were denied by Windows Mandatory Integrity Control (Low Integrity), and outbound raw socket creation was prohibited. The attacker could not run cmd.exe or persist.

Stage 3: Windows Kernel ALPC Pool Overflow (CVE-2026-85880)

To escape the sandbox, the attacker leveraged the fact that sandboxed renderers must still communicate with system IPC endpoints via ALPC. The attacker sent an intricately malformed ALPC message structure with mismatched message length headers. In ntoskrnl.exe, the message handling routine allocated a kernel pool buffer based on the declared data size, but copied data based on the total message length, triggering an out-of-bounds heap write into the adjacent Paged Pool. The attacker corrupted an adjacent security token object to grant themselves SeDebugPrivilege and SYSTEM credentials.

漏洞机制 vs 生产纵深防御对比

VULNERABLE: TURBOFAN RANGE INFERENCE & ALPC BUFFER COPY
// 1. Conceptual V8 Turbofan Typer Flaw (CVE-2026-87491)
Type Typer::Visitor::TypeSpeculativeNumberBitwiseOr(Node* node) {
  // Bug: Underflow/truncation in 64-bit range inference
  // Compiler statically infers range [0, 10], but runtime value can reach 0x7FFFFFFF!
  return Type::Range(min_val, max_val, zone()); 
}

// 2. Conceptual Windows Kernel ALPC Heap Copy Flaw (CVE-2026-85880)
NTSTATUS AlpcpCopyMessageData(PALPC_MESSAGE Msg, PVOID Buffer) {
  // Bug: Buffer allocated from declared DataLength, but copy uses TotalLength
  ULONG allocSize = Msg->Header.u1.s1.DataLength;
  PVOID poolBlock = ExAllocatePoolWithTag(PagedPool, allocSize, 'CplA');
  
  // HEAP OVERFLOW: TotalLength > DataLength overwrites adjacent pool memory!
  RtlCopyMemory(poolBlock, Msg->PortMessage.Data, Msg->Header.u1.s1.TotalLength);
  return STATUS_SUCCESS;
}
HARDENED: CLAMPED RANGE ASSERTION & SIZE VALIDATION
// 1. Fixed V8 Turbofan Bounds Validation
Type Typer::Visitor::TypeSpeculativeNumberBitwiseOr(Node* node) {
  // Fix: Strict conservative bounding preventing speculative check elimination
  if (!IsSafeIntegerRange(min_val, max_val)) return Type::Any();
  return Type::Range(SafeClamp(min_val), SafeClamp(max_val), zone());
}

// 2. Fixed Windows Kernel ALPC Size Verification
NTSTATUS AlpcpCopyMessageData(PALPC_MESSAGE Msg, PVOID Buffer) {
  // Fix: Explicit sanity check validating header length consistency
  if (Msg->Header.u1.s1.TotalLength < Msg->Header.u1.s1.DataLength) {
    return STATUS_INVALID_PARAMETER;
  }
  // Allocate buffer matching the actual copy length, strictly bounded
  PVOID poolBlock = ExAllocatePoolWithTag(PagedPool, Msg->Header.u1.s1.TotalLength, 'CplA');
  if (!poolBlock) return STATUS_INSUFFICIENT_RESOURCES;
  RtlCopyMemory(poolBlock, Msg->PortMessage.Data, Msg->Header.u1.s1.TotalLength);
  return STATUS_SUCCESS;
}

端点监控与遥测检测规则

# Sysmon Event ID 1: Detect suspicious child processes spawned from chrome.exe EventID=1 AND ParentImage="*\chrome.exe" AND Image IN ("*\cmd.exe", "*\powershell.exe", "*\whoami.exe") # ETW: Microsoft-Windows-Kernel-Memory: Monitor NonPaged/Paged Pool ALPC corruption logman start AlpcPoolTrace -p "Microsoft-Windows-Kernel-Memory" 0x80 -ets # Yara: Rule targeting the BlueMoon V8 JIT shellcode loader stage rule BlueMoon_V8_Stage1 { strings: $c = { 48 8B 04 24 48 83 C0 ?? 48 89 04 24 } condition: $c }
Enable Windows Exploit Guard and Virtualization-Based Security (VBS) with Kernel DMA Protection to stop arbitrary kernel token overwrite techniques.

系统架构师防范指南与清单

参考来源与官方公告