Chinese State‑Aligned Groups Exploit Triple Zero‑Day Chain in Chrome, Chromium, and Windows to Gain System Privileges
What Happened — Proofpoint observed at least four Chinese‑aligned espionage groups chaining three zero‑day vulnerabilities (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880) to run code in the browser sandbox, escape it, and obtain system‑level privileges on Windows machines. The attacks began on Aug 28 2024, were delivered via phishing lures masquerading as a “Google Gemini” extension, and targeted NGOs, mining firms, and commodity‑trading companies in the United States.
Why It Matters for Trust & Control Assurance
- Highlights the risk of unpatched software and the need for continuous vulnerability monitoring that can be documented as audit evidence.
- Demonstrates how a rapid exploit chain can bypass traditional perimeter defenses, underscoring the importance of control mapping and evidence collection for patch‑management and privileged‑access controls.
- Provides a concrete scenario where a control‑assurance program must prove timely remediation and defensible logs to satisfy multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – Non‑governmental organizations, mining companies, commodity‑trading firms, and any enterprise that relies on Chrome/Chromium browsers or Windows 10/11 without the latest patches.
Recommended Actions – Verify that all Chrome/Chromium browsers and Windows endpoints are updated to the latest releases; deploy continuous vulnerability scanning and integrate findings into a centralized control‑assurance dashboard; retain patch‑deployment logs as evidence for audit readiness. Source: https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days
Technical Notes – The exploit chain (named “BlueMoon”) combines two remote‑code‑execution flaws in Chromium’s V8 JavaScript engine and a privilege‑escalation flaw in Windows Advanced Local Procedure Call (ALPC). All three were exploited before public patches were available; the V8 bugs were patched in source but not yet in released browsers. Delivery was via phishing emails with a malicious browser extension. Source: https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days