BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Reported exploitedGoogle ChromeViolet TyphoonV8 EngineOur summary
Proofpoint has reported active in-the-wild exploitation by a new exploit kit named BlueMoon, which chains three previously unpatched vulnerabilities to target espionage-driven campaigns. The attack sequence combines two Google Chrome V8 engine zero-days, identified as CVE-2026-85046 and CVE-2026-87491, with a Microsoft Windows privilege escalation flaw in the Advanced Local Procedure Call component tracked as CVE-2026-85880.
Multiple China-linked threat actors, including Violet Typhoon, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, have rapidly adopted this toolkit for attacks on NGOs, aerospace firms, and government entities. While the Chrome vulnerabilities were addressed on September 3 and September 8, the Windows defect was resolved during the September 2026 Patch Tuesday cycle, underscoring the urgent need for immediate patching across affected systems.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.