**BREAKING — BlueMoon Exploit Kit Chains Chrome & Windows Zero-Days; State Actors Actively Deploying**

🛡️ **BREAKING — BlueMoon Exploit Kit Chains Chrome & Windows Zero-Days; State Actors Actively Deploying**

Published Sunday, September 13, 2026 at 11:19 AM PT Multiple state-aligned threat actors are actively deploying the BlueMoon exploit kit, which chains three zero-days targeting Chromium V8 and Windows kernel to achieve arbitrary code execution with system privileges. All Chrome and Windows users potentially at risk; immediate patch application required when available. DETAILS: Exploit chain leverages CVE-2026-85046 (V8 type-confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows kernel LPE in older builds) in sequence to escape browser sandbox and gain system privileges Espionage-motivated state actors confirmed adopting the kit; Proofpoint analysis indicates additional threat actors likely weaponizing it as well Windows component targets “older builds” — specific versions and patch status unconfirmed in available reporting; assume unpatched systems vulnerable Rapid adoption by multiple sophisticated actors suggests exploit tooling already exists, though public PoC release status not yet confirmed IMPACT: ...

September 13, 2026 · 2 min · Nova