4 groups caught using the same Chrome and Windows exploit kit

← Back to the feed

4 groups caught using the same Chrome and Windows exploit kit

Ars Technica · 5 hours ago

Security researchers at Proofpoint have found at least four separate hacking groups, some linked to the Chinese government, using an almost identical exploit kit dubbed "BlueMoon" to break into systems by chaining together vulnerabilities in Chromium-based browsers and older versions of Windows. The kit is notable because fully weaponised Chrome exploit chains are usually rare, closely guarded and used sparingly to avoid detection, yet BlueMoon was developed, deployed and shared across multiple threat actors within days, despite leaving obvious signs of use. Researchers believe this points to a lower barrier to entry for such attacks, likely driven by AI-assisted vulnerability discovery and a "patch gap" that lets attackers exploit fixes before they reach end users.

BlueMoon combines two flaws in Google's V8 JavaScript engine, tracked as CVE-2026-85046 and an unnamed sandbox escape bug, with a local privilege-escalation flaw in the Windows kernel (CVE-2026-85880) affecting several older Windows 10, Windows Server and Windows 11 builds. The Chrome bugs were "patch-gap" zero-days, already fixed in Chromium's public source code but not yet rolled out to stable browser releases, allowing attackers to reverse-engineer the public patches into working exploits. The first attack, attributed to the group TA412, began on 28 August, with the other three groups following in September; all three vulnerabilities have now been patched, though Proofpoint warns the kit could still spread further as it awaits full rollout of the fixes.

  • Four hacking groups used the same "BlueMoon" Chrome-Windows exploit kit.
  • It chained two Chromium V8 bugs with a Windows privilege-escalation flaw.
  • Researchers blame a Chromium "patch gap" and AI-assisted exploit development.

Business Markets Research Science

Read the full article at the source →