Published Sunday, September 13, 2026 at 11:19 AM PT

<strong>BREAKING — BlueMoon Exploit Kit Chains Chrome & Windows Zero-Days; State Actors Actively Deploying</strong>

Multiple state-aligned threat actors are actively deploying the BlueMoon exploit kit, which chains three zero-days targeting Chromium V8 and Windows kernel to achieve arbitrary code execution with system privileges. All Chrome and Windows users potentially at risk; immediate patch application required when available.

DETAILS:

  • Exploit chain leverages CVE-2026-85046 (V8 type-confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows kernel LPE in older builds) in sequence to escape browser sandbox and gain system privileges
  • Espionage-motivated state actors confirmed adopting the kit; Proofpoint analysis indicates additional threat actors likely weaponizing it as well
  • Windows component targets “older builds” — specific versions and patch status unconfirmed in available reporting; assume unpatched systems vulnerable
  • Rapid adoption by multiple sophisticated actors suggests exploit tooling already exists, though public PoC release status not yet confirmed

IMPACT:

  • All Chromium-based browsers (Chrome, Edge, Brave, etc.) and older Windows kernels potentially exploitable
  • High-value targeting: government, defense, critical infrastructure confirmed targets of these actor groups; broader campaigns likely active
  • Scope assessed as state-level espionage; organizations tracking advanced persistent threats should assume active compromise attempts underway

RECOMMENDED ACTIONS:

  • Immediate: Verify Chrome/Chromium auto-update enabled; validate patches applied within hours of release
  • Near-term: Audit Windows patch levels; identify systems on older builds and prioritize upgrades
  • Detection: Flag V8 crashes, sandbox escape patterns, and kernel-mode execution via Chrome process trees
  • Monitoring: Track Proofpoint, BleepingComputer, SecurityWeek, Huntress for patch status and targeting indicators

SOURCES:

Proofpoint (“Once in a BlueMoon”) | BleepingComputer | SecurityWeek | Huntress | news4hackers | sploitus


Recent high-severity events at publish time:

Recent high-severity events