CLEANGULP Exploit Chain: Chaining Chrome V8 Sandbox Breakout with Windows ALPC Kernel Zero-Day

CLEANGULP Exploit Chain Chrome V8 to Windows ALPC

Threat intelligence researchers have uncovered a state-backed cyber espionage campaign dubbed CLEANGULP. The threat actor chained an unpatched type-confusion vulnerability in Google Chrome’s V8 JavaScript engine with Microsoft’s recently disclosed Windows Advanced Local Procedure Call (ALPC) zero-day (CVE-2026-85880), achieving seamless remote code execution and full Windows kernel SYSTEM elevation.

Exploit Chain Anatomy

[1. Malicious Web Page]
       │
       ▼ (Chrome V8 Type Confusion)
[2. Renderer Process Compromised] -> Sandboxed Child Process
       │
       ▼ (Sandbox Escape via ALPC Message)
[3. Windows ALPC Heap Overflow: CVE-2026-85880]
       │
       ▼ (Overwrites struct _KPROCESS token)
[4. SYSTEM Privilege Escalation] -> Interactive Kernel Ring-0 Takeover

Stage 1: V8 Engine Type Confusion (Sandbox Escape)

The attack initiates when a victim navigates to an attacker-controlled watering-hole website. A crafted JavaScript payload induces a type confusion condition in Chrome's TurboFan compiler, granting read/write primitive access inside the renderer process memory space.

Stage 2: Windows ALPC Heap Overflow (CVE-2026-85880)

From within the sandboxed Chrome renderer process, the exploit communicates with the Windows kernel via the ALPC port subsystem. By dispatching a malformed ALPC message structure with an irregular buffer length, the exploit triggers a heap-based buffer overflow inside ntoskrnl.exe, corrupting the target process's security token and elevating privileges from restricted sandbox to NT AUTHORITY\SYSTEM.

Detection Signatures & Behavioral Telemetry

SOC teams can detect CLEANGULP activity by identifying unexpected ALPC port connections origin from browser processes:

# Sigma Rule: Chrome Renderer Spawning Privileged System Utility
title: CLEANGULP Exploit Chain Execution
status: experimental
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith: 'chrome.exe'
        Image|endswith:
            - 'cmd.exe'
            - 'powershell.exe'
            - 'whoami.exe'
        IntegrityLevel: 'System'
    condition: selection
level: critical

Defense & Mitigation

  1. Update Web Browsers: Deploy Chrome 128.0.6613.120+ or latest Chromium-based enterprise builds.
  2. Apply Microsoft September 2026 Updates: Ensure CVE-2026-85880 is patched across all enterprise Windows desktop fleets.
  3. Implement Browser Isolation: Utilize Remote Browser Isolation (RBI) for users accessing untrusted external web destinations.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther