← All articles

BlueMoon exploit kit chains Chrome and Windows zero-days to reach SYSTEM

Researchers at Proofpoint and Volexity detailed BlueMoon, a modular exploit kit that chains three zero-day flaws to take a victim from a malicious web page to full control of their Windows machine. It uses two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to run code in the browser and escape its sandbox, then a Windows kernel bug, CVE-2026-85880, to gain SYSTEM privileges. Both Chrome flaws were "patch-gap" zero-days: their fixes were already public in Chromium's open source before reaching stable Chrome, so attackers reverse-engineered the fixes to hit users who had not yet updated. Multiple espionage groups adopted the shared kit within days, and researchers expect wider use.

Check
Update Chrome and Chromium-based browsers and apply Windows patches immediately, since all three chained flaws are fixed, and prioritize browser updates because attackers weaponize public Chromium fixes before they reach stable releases.
Affected
Users on outdated Chrome or Chromium browsers and unpatched Windows; the kit chains browser code execution, sandbox escape, and a kernel flaw to reach SYSTEM from a single web page.
Fix
Keep browsers and operating systems updated aggressively and automatically, treat a public browser-engine fix as a signal to update fast, deploy the vendors' indicators, and reduce exposure to drive-by web attacks.