BlueMoon exploit kit chains Chrome and Windows zero-days to reach SYSTEM
Researchers at Proofpoint and Volexity detailed BlueMoon, a modular exploit kit that chains three zero-day flaws to take a victim from a malicious web page to full control of their Windows machine. It uses two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to run code in the browser and escape its sandbox, then a Windows kernel bug, CVE-2026-85880, to gain SYSTEM privileges. Both Chrome flaws were "patch-gap" zero-days: their fixes were already public in Chromium's open source before reaching stable Chrome, so attackers reverse-engineered the fixes to hit users who had not yet updated. Multiple espionage groups adopted the shared kit within days, and researchers expect wider use.
- Check
- Update Chrome and Chromium-based browsers and apply Windows patches immediately, since all three chained flaws are fixed, and prioritize browser updates because attackers weaponize public Chromium fixes before they reach stable releases.
- Affected
- Users on outdated Chrome or Chromium browsers and unpatched Windows; the kit chains browser code execution, sandbox escape, and a kernel flaw to reach SYSTEM from a single web page.
- Fix
- Keep browsers and operating systems updated aggressively and automatically, treat a public browser-engine fix as a signal to update fast, deploy the vendors' indicators, and reduce exposure to drive-by web attacks.