CVE-2026-85880 is a heap-based buffer overflow in the Windows kernel's ALPC (asynchronous local procedure call) component, used as the local privilege escalation stage of the "BlueMoon" browser exploit chain. After CVE-2026-85046 and CVE-2026-87491 compromise the Chrome V8 sandbox, this kernel flaw lets an attacker escape Chrome's sandboxed renderer process and inject code into the Chrome browser process, from which a payload of the actor's choice is deployed. It overlaps with one of the two actively exploited Windows zero-days patched in Microsoft's September 2026 Patch Tuesday release, and was added to the CISA Known Exploited Vulnerabilities catalogue.
Multiple Chinese-linked espionage groups used the identical chain, indicating shared exploit brokering or supply.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-85880 |
| Type | Heap-based buffer overflow (Windows kernel / ALPC) |
| Exploited | In the wild (Chrome chain, AugโSep 2026) |
| Chain | CVE-2026-85046 + CVE-2026-87491 + CVE-2026-85880 |
| Source | Volexity โ Tier 1/4 |