**BlueMoon Exploit Kit Chains Chromium and Windows Flaws in Targeted Attacks** Proofpoint documented an exploit kit called BlueMoon that chain-linked two Chromium vulnerabilities (CVE-2026-85046 for V8 memory access and CVE-2026-87491 for V8 sandbox escape) with a Windows local privilege-escalation flaw (CVE-2026-85880) in attacks on Chrome users on Windows from late August into early September 2026. The kit was used by APT31 (Violet Typhoon) and UTA0560 in spearphishing campaigns targeting NGOs, aerospace, and manufacturing organizations, with delivery themed around donations, business cooperation, file sharing, and meeting invitations. Google patched the Chrome bugs on September 3 and 8, Microsoft addressed the Windows flaw in its September Patch Tuesday, and CISA later added all three to its Known Exploited Vulnerabilities catalog; researchers noted that BlueMoon maintainers exploited the gap between public Chromium fixes and Stable Chrome releases by reverse-engineering code changes before downstream users received updates.
The Patch Gap Wasn't a Mistake — It Was the Architecture of Access
Let's be very clear about what you just read. Four espionage groups, using the exact same exploit chain, within days. Not competitors. Not rivals. They all accessed the same kit. BlueMoon isn't just a toolkit you buy on a forum — it's a distribution mechanism designed by people who know precisely how the Open Source Theatre works. Google publicly commits code fixes to the Chromium repository, and then the exploit maintainers simply reverse-engineer those patches before ordinary users ever get the update. That's not a gap. That's a timed window deliberately left open. Ask yourself: how many of those "patches" are surface-level theater, while deeper vulnerabilities remain unaddressed because they've already been integrated into someone's long-term intelligence pipeline?
Your Browser and Your Windows Kernel Are Being Rented, Not Owned
Look at the target list. NGOs. Aerospace. Manufacturing. These aren't random victims — these are the institutions that manage logistics, supply chains, and humanitarian operations. The attackers didn't need a nation-state's zero-day stockpile. They used Chrome, then Windows ALPC, chaining two publicly known Chromium flaws from the open-source repository. The message is clear: the core infrastructure of your digital life has been hollowed out. Browser sandbox escape into kernel-level persistence isn't exotic anymore. It's packaged. It's reusable. It's handed out to four different groups by the same maintenance team. The exploit eliminated the gap between "browser" and "operating system" — and by doing so, it also eliminated the line between "corporate espionage" and "state-sponsored data exfiltration."
The Phishing Lures Are Your Mirror — They Know What You Care About
Donation requests. Business partnership offers. File-sharing notifications. Meeting invitations. Every single vector is designed to weaponize whatever you, personally, consider urgent or valid. The attackers didn't need to guess your password, because they already owned the medium of interaction. BlueMoon was deployed to NGOs working with vulnerable populations, and aerospace firms managing defense supply chains. Focus on what connects them, not what separates them. When you see four distinct intelligence outfits using the same exploit chain, on the same CVE schedule, targeting the same sectoral pattern, you must ask: who is orchestrating the permission to access? Who decides which environmental groups, or which space contractors, are left exposed at the end of this distribution graph? The flaw isn't in the kernel. The flaw is in the system of who gets to exploit the gap between transparency and security — and that system, like every one of these CVEs, is fully documented if you know where to look.






