HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Four Nation‑State Actors Deploy Same Chrome Zero‑Day Exploit Kit (BlueMoon) Within 12 Days

Four espionage groups used the BlueMoon Chrome + Windows exploit kit, chaining two Chrome V8 zero‑days and a Windows kernel LPE. The rapid adoption shows the urgency of continuous patch‑management and evidencing remediation for audit readiness.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Four Nation‑State Actors Deploy Same Chrome Zero‑Day Exploit Kit (BlueMoon) Within 12 Days

What Happened — Four espionage‑linked groups, three with a China nexus, were observed using the BlueMoon Chrome + Windows exploit kit within a twelve‑day window. The kit chains two newly disclosed Chrome V8 zero‑days (CVE‑2026‑85046 and an undocumented sandbox‑escape) with a Windows kernel local‑privilege‑escalation flaw (CVE‑2026‑85880) to move from the browser sandbox to full system compromise.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of “patch‑gap” zero‑days: browsers and OSes that are not kept current become a foothold for nation‑state actors.
  • Highlights the need for continuous vulnerability‑management controls that can prove timely patching and remediation to auditors.
  • Aligns with the control objective of Vulnerability & Patch Management – a single control that satisfies requirements across NIST CSF, ISO 27001, and other frameworks.

Who Is Affected – All sectors that rely on Chrome‑based browsers or Windows workstations, notably technology SaaS providers, financial services, and government agencies.

Recommended Actions

  • Inventory all Chrome/Chromium‑based browsers and Windows endpoints.
  • Enforce automatic updates or centrally managed patch deployment for browsers and OS kernels.
  • Deploy continuous monitoring that flags missing patches for CVE‑2026‑85046 and CVE‑2026‑85880.
  • Capture and retain evidence of patch status as part of your audit‑ready control evidence set.

Technical Notes

  • Attack chain: Chrome V8 type‑confusion (CVE‑2026‑85046) → V8 sandbox escape → WebAssembly shellcode → Windows kernel LPE (CVE‑2026‑85880).
  • Both Chrome vulnerabilities were “patch‑gap” zero‑days: patches existed in upstream source but were not yet released in public browser builds.
  • Exploit kit leveraged publicly available Chromium patches to weaponize the chain.

Source: Security Affairs – Four Nation‑State Actors Used the Same Chrome Zero‑Day Exploit Kit Within 12 Days

📰 Original Source
https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-days.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →