
Security researchers at Proofpoint identified an exploit kit called BlueMoon being used by at least four threat actors, including groups with Chinese government connections. The toolkit chains together multiple vulnerabilities affecting Chromium-based browsers and older Windows systems to enable malicious code execution with elevated privileges.
The exploit kit targets two vulnerabilities in Google’s V8 JavaScript engine used by Chrome, designated CVE-2026-85046 and an undesignated sandbox escape, alongside a Windows kernel flaw tracked as CVE-2026-85880. These vulnerabilities affect Windows 10, Windows 10 2004, Windows Server 2019, Windows Server 2022, and initial Windows 11 releases. All three vulnerabilities received patches within the 24-hour period preceding the researchers’ disclosure.
Proofpoint attributed the rapid development and broad deployment of BlueMoon to multiple factors. The firm identified a critical timing advantage stemming from the “patch gap” in the Chromium supply chain—the interval between when developers release patches and when those patches are incorporated into stable browser releases. Additionally, researchers suggested that artificial intelligence tools may be enabling threat actors to identify and weaponize vulnerabilities more quickly than traditional human-driven discovery methods would allow.
The observed attacks demonstrated unusually high visibility compared to typical exploitation campaigns, which often prioritize stealth to maximize a vulnerability’s operational lifespan. Proofpoint noted that historically, functional Chrome exploit chains represented rare, high-value capabilities among threat actors. The rapid sharing of BlueMoon across multiple groups within days, combined with substantial detection signals, indicated a potential shift in the threat landscape. The researchers suggested that AI-assisted development and the public availability of upstream Chromium patches may have substantially reduced both the technical barriers and development costs for creating weaponized browser exploits.
The initial attacks using BlueMoon began in late August, with additional campaigns deployed earlier this month. Proofpoint indicated that while all three underlying vulnerabilities have been patched, the toolkit may continue circulating as patches roll out across various Chromium-based browsers and as additional threat actors potentially adopt the capability.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI