High

BlueMoon, Exploit Kit, Chrome, V8, Windows, Zero-Day, APT, Proofpoint

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

The BlueMoon exploit kit chains two Chrome V8 zero-days and a Windows ALPC privilege-escalation bug into a browser-to-SYSTEM attack, and multiple China-linked APTs are using it.

The BlueMoon exploit kit is a new browser-to-SYSTEM attack toolkit that chains two Chrome V8 zero-days and a Windows privilege-escalation zero-day into a single drive-by chain, and multiple China-linked espionage groups have already adopted it, according to Proofpoint. The China-linked APT Violet Typhoon (also tracked as APT31) was first to use it on August 28, 2026, and within days several other Chinese threat actors followed, with signs the activity may not stay exclusive to China-aligned groups. Proofpoint warns that its ease of adoption makes further proliferation to both espionage and financially motivated actors likely.

BlueMoon chains three flaws that were all unpatched when it emerged. The two Chrome bugs, CVE-2026-85046 and CVE-2026-87491, both affect the V8 JavaScript and WebAssembly engine and were patched as zero-days on September 3 and September 8, 2026. The Windows bug, CVE-2026-85880, is a heap-based privilege escalation in the Advanced Local Procedure Call (ALPC) subsystem fixed in the September 2026 Patch Tuesday. All three are now in the CISA KEV catalog.

The chain works in sequence: BlueMoon exploits the V8 defects to escape the browser sandbox, fingerprints the host, then runs the ALPC privilege escalation. A CreateProcess stub is injected into the parent Chrome broker process to download an executable via curl and run it. Proofpoint found several packaging variants sharing the same exploit chain and orchestration, and development artifacts that suggest, without confirming, that the kit's authors may have used AI to build it.

Who is being targeted by BlueMoon?

Violet Typhoon initially used it against NGOs in the US, plus mining and physical commodity trading firms. From September 2, a second China-linked group tracked as UNK_LateNight aimed it at multiple US aerospace companies, and a separate actor tracked as UNK_DoubleCheck hit a manufacturing organization. The victimology is classic espionage: policy, defense-industrial, and critical-manufacturing targets, delivered opportunistically through a shared kit rather than a single actor's bespoke tooling.

Why does a shared exploit kit change the threat model?

Because it decouples capability from resources. Historically, chaining multiple zero-days required a well-funded team; a packaged kit lets many unrelated actors run the same browser-to-SYSTEM chain with little effort. That is the same collapse of the tooling gap now visible across the threat landscape, and it means a single unpatched browser or missed Patch Tuesday can expose an endpoint to several distinct groups at once, not just one.

Detail

Value

Name

BlueMoon exploit kit

Chain

CVE-2026-85046 + CVE-2026-87491 (Chrome V8) then CVE-2026-85880 (Windows ALPC)

Effect

Sandbox escape to privilege escalation to code execution

First seen

Violet Typhoon (APT31), August 28, 2026

Adopters

Multiple China-linked APTs; likely to proliferate

Status

All three CVEs patched and in CISA KEV

Our read

BlueMoon is a preview of a threat model where zero-day chains are commodities, not the exclusive tooling of elite teams. The individual bugs are already patched and in KEV, so the practical defense is unglamorous and effective: keep browsers and Windows patched on a fast, verified cadence, because this chain only works against endpoints that missed the September updates. The broader lesson is that the labor gap separating well-resourced operators from everyone else is closing, so defenders should assume capable exploitation of any recently disclosed, browser-reachable bug and verify their fleet is actually updated rather than trusting auto-update.

Reporting and attribution per SecurityWeek and Proofpoint; CVE and KEV status per NVD and CISA. Sources linked above.

Related: Chrome V8 zero-day CVE-2026-85046 and What is privilege escalation?.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.