CVE Tools

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

SecurityWeekBy Ionut Arghire

Reported exploitedGoogle ChromeViolet TyphoonV8 Engine

Our summary

Proofpoint has reported active in-the-wild exploitation by a new exploit kit named BlueMoon, which chains three previously unpatched vulnerabilities to target espionage-driven campaigns. The attack sequence combines two Google Chrome V8 engine zero-days, identified as CVE-2026-85046 and CVE-2026-87491, with a Microsoft Windows privilege escalation flaw in the Advanced Local Procedure Call component tracked as CVE-2026-85880.

Multiple China-linked threat actors, including Violet Typhoon, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, have rapidly adopted this toolkit for attacks on NGOs, aerospace firms, and government entities. While the Chrome vulnerabilities were addressed on September 3 and September 8, the Windows defect was resolved during the September 2026 Patch Tuesday cycle, underscoring the urgent need for immediate patching across affected systems.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store