HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Chinese State‑Aligned Groups Exploit Triple Zero‑Day Chain in Chrome, Chromium, and Windows to Gain System Privileges

Proofpoint tracked four Chinese‑aligned espionage groups chaining three zero‑day flaws (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880) to escape browser sandboxes and obtain Windows system privileges. The campaign hit NGOs, mining and commodity‑trading firms in the U.S. before patches were public, underscoring the need for robust vulnerability‑management evidence for audit readiness.

LiveThreat™ Intelligence · 📅 September 11, 2026· 📰 proofpoint.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
proofpoint.com

Chinese State‑Aligned Groups Exploit Triple Zero‑Day Chain in Chrome, Chromium, and Windows to Gain System Privileges

What Happened — Proofpoint observed at least four Chinese‑aligned espionage groups chaining three zero‑day vulnerabilities (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880) to run code in the browser sandbox, escape it, and obtain system‑level privileges on Windows machines. The attacks began on Aug 28 2024, were delivered via phishing lures masquerading as a “Google Gemini” extension, and targeted NGOs, mining firms, and commodity‑trading companies in the United States.

Why It Matters for Trust & Control Assurance

  • Highlights the risk of unpatched software and the need for continuous vulnerability monitoring that can be documented as audit evidence.
  • Demonstrates how a rapid exploit chain can bypass traditional perimeter defenses, underscoring the importance of control mapping and evidence collection for patch‑management and privileged‑access controls.
  • Provides a concrete scenario where a control‑assurance program must prove timely remediation and defensible logs to satisfy multiple frameworks (e.g., NIST CSF, ISO 27001).

Who Is Affected – Non‑governmental organizations, mining companies, commodity‑trading firms, and any enterprise that relies on Chrome/Chromium browsers or Windows 10/11 without the latest patches.

Recommended Actions – Verify that all Chrome/Chromium browsers and Windows endpoints are updated to the latest releases; deploy continuous vulnerability scanning and integrate findings into a centralized control‑assurance dashboard; retain patch‑deployment logs as evidence for audit readiness. Source: https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days

Technical Notes – The exploit chain (named “BlueMoon”) combines two remote‑code‑execution flaws in Chromium’s V8 JavaScript engine and a privilege‑escalation flaw in Windows Advanced Local Procedure Call (ALPC). All three were exploited before public patches were available; the V8 bugs were patched in source but not yet in released browsers. Delivery was via phishing emails with a malicious browser extension. Source: https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days

📰 Original Source
https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →