Four Nation‑State Actors Deploy Same Chrome Zero‑Day Exploit Kit (BlueMoon) Within 12 Days
What Happened — Four espionage‑linked groups, three with a China nexus, were observed using the BlueMoon Chrome + Windows exploit kit within a twelve‑day window. The kit chains two newly disclosed Chrome V8 zero‑days (CVE‑2026‑85046 and an undocumented sandbox‑escape) with a Windows kernel local‑privilege‑escalation flaw (CVE‑2026‑85880) to move from the browser sandbox to full system compromise.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of “patch‑gap” zero‑days: browsers and OSes that are not kept current become a foothold for nation‑state actors.
- Highlights the need for continuous vulnerability‑management controls that can prove timely patching and remediation to auditors.
- Aligns with the control objective of Vulnerability & Patch Management – a single control that satisfies requirements across NIST CSF, ISO 27001, and other frameworks.
Who Is Affected – All sectors that rely on Chrome‑based browsers or Windows workstations, notably technology SaaS providers, financial services, and government agencies.
Recommended Actions
- Inventory all Chrome/Chromium‑based browsers and Windows endpoints.
- Enforce automatic updates or centrally managed patch deployment for browsers and OS kernels.
- Deploy continuous monitoring that flags missing patches for CVE‑2026‑85046 and CVE‑2026‑85880.
- Capture and retain evidence of patch status as part of your audit‑ready control evidence set.
Technical Notes
- Attack chain: Chrome V8 type‑confusion (CVE‑2026‑85046) → V8 sandbox escape → WebAssembly shellcode → Windows kernel LPE (CVE‑2026‑85880).
- Both Chrome vulnerabilities were “patch‑gap” zero‑days: patches existed in upstream source but were not yet released in public browser builds.
- Exploit kit leveraged publicly available Chromium patches to weaponize the chain.
Source: Security Affairs – Four Nation‑State Actors Used the Same Chrome Zero‑Day Exploit Kit Within 12 Days