Multiple State‑Aligned Threat Actors Rapidly Adopt Chrome & Windows Zero‑Day Exploit Chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880)
What It Is – Proofpoint’s Threat Insight team observed a new exploit kit, dubbed BlueMoon, that chains three zero‑day flaws: two in Chromium’s V8 JavaScript engine (CVE‑2026‑85046, CVE‑2026‑87491) and a Windows kernel local‑privilege‑escalation bug (CVE‑2026‑85880). The kit has been adopted within days by several espionage‑motivated, state‑aligned groups, primarily China‑linked, and may spread to financially motivated actors as patches roll out.
Exploitability – All three vulnerabilities were unpatched (“patch‑gap” zero‑days) at the time of first use. Proofpoint reports active exploitation in the wild; no public proof‑of‑concept is required for an attacker to weaponize the chain once a patched binary is released.
Affected Products – Google Chrome and Chromium‑based browsers (any version that had not yet received the upstream V8 patches) and Microsoft Windows operating systems prior to the release of the kernel LPE fix.
Why It Matters for Trust & Control Assurance
- Vulnerability‑management control – The rapid, cross‑actor adoption highlights the need for continuous, evidence‑driven patch‑tracking rather than periodic checks.
- Audit‑ready evidence – Demonstrating that you have up‑to‑date remediation evidence for browser and OS patches satisfies multiple framework objectives (e.g., NIST CSF “Detect” and ISO 27001 “Asset Management”).
- Supply‑chain vigilance – The exploit kit’s reuse across unrelated groups shows that a single unpatched component can become a shared attack surface, demanding a unified view of third‑party and internal asset exposure.
Recommended Actions
- Verify that all Chrome/Chromium browsers and Windows endpoints are running the latest patches that address CVE‑2026‑85046, CVE‑2026‑87491, and CVE‑2026‑85880.
- Enable continuous vulnerability‑management tooling that automatically collects patch‑status evidence and maps it to your control framework.
- Review your incident‑response playbooks for zero‑day exploitation scenarios, ensuring forensic logging is enabled on browsers and OS kernels.