Skip to content

Leadership1 publisher3 min readPublished

Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source

Proofpoint says a shared toolkit called BlueMoon chained two V8 flaws that Chromium had fixed in public but Chrome had not yet shipped, plus a Windows kernel bug that elevates only on older builds.

The Board Room · Leadership desk

What happened

  • Proofpoint, working with Google's Threat Intelligence Group, Microsoft's Threat Intelligence Center and Volexity, named a toolkit BlueMoon that chains Chrome and Windows flaws for spear phishing campaigns.
  • The third, CVE-2026-85880, is a Windows kernel local privilege escalation zero-day found in older Windows builds, and all three vulnerabilities are rated high severity.
  • Lures included posing as students seeking internships and conference outreach, with clickers sent to an actor-controlled domain, held on a loading page, then redirected to sites such as GitHub.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint A metric that counts endpoints on the vendor's current stable release cannot see this exposure, because the vulnerable build was the current one. The customer absorbs a delay created upstream.
  • decision The privilege escalation only lands on Windows 10 22H2 and Windows 11 21H2, so the OS refresh queue decides whether a successful click ends in the browser or at administrator level.
  • precedent A kit shared across four clusters lowers the price of a Chrome exploit chain, so threat models that reserved full chains for a handful of state operators need repricing.
  • contradiction The public account counts four vulnerabilities in the chain but names three CVEs. Anyone scoping mitigations from it is one component short.

The latency in this chain sat inside Google's release pipeline. Proofpoint's framing is the precise one: at the Chromium source level CVE-2026-85046 was an N-day, known and already patched, while in Google Chrome it was effectively a zero-day [12]. Both V8 bugs in the kit fit that description, fixed in public upstream code and still unpatched in later stable releases of Chrome and Chromium-based browsers [8]. An endpoint running the newest stable build was exploitable.

The dates give an outer bound. A security researcher reported CVE-2026-85046 to the Chromium project on August 4, and a fix went into the open source codebase. Because it had not reached newer Chrome versions, the researchers described an "unusual patch gap" [9]. That report came 24 days before the first observed BlueMoon campaign [19]. The CSO Online account does not say when the fix shipped in a stable Chrome release, so those 24 days measure the interval to exploitation and not the gap itself [20].

Seva Ioussoufovitch, senior research analyst at Info-Tech Research Group, said "Attackers are acting faster, and that means each day a patch is delayed carries more risk than it used to" [11]. He also said the ability to build exploit kits has been "wildly accelerated" by AI, and that actors likely had time to reverse engineer working exploits from the open source codebase [10]. A security owner can compress their own deployment lag from weeks to days, but the upstream-to-stable interval is outside their control. What is left inside their control is compensating controls and detection. On detection, Proofpoint noted that BlueMoon was "developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals" [3].

One link does sit in the asset inventory. CVE-2026-85880 is a Windows kernel privilege escalation, and Ioussoufovitch described it as elevating privileges on older Windows instances, specifically Windows 10 22H2 and Windows 11 21H2 [6]. Without that step the chain gets arbitrary code execution inside the browser from a click on a phishing link [6]. With it, in his words, "BlueMoon enables threat actors to gain full Windows admin privileges in one click, and install whatever malware they want on an endpoint" [7].

This is one kit, aimed at a small number of US NGOs, mining companies and physical commodity trading firms, with high detection signals, and the two V8 bugs are now fixed [14] [3]. What lasts is the distribution. Proofpoint said that within days of the August campaign several other espionage-motivated clusters began using BlueMoon, most with a suspected China nexus [16], and Nick Tausek, lead security automation architect at Swimlane, said use across four clusters makes it look "less like a specialized weapon and more like reusable infrastructure" [18]. Proofpoint's observation that "a fully weaponized Chrome exploit chain has historically been a high-value, rare capability" describes the price before this kit [13]. Proofpoint predicted BlueMoon will "likely proliferate further and be adopted by both espionage-motivated and financially motivated threat actors" [17].

What to watch

  • Whether Google changes how quickly upstream Chromium security fixes reach stable Chrome builds.
  • Whether financially motivated actors adopt BlueMoon, as Proofpoint predicted they would.
  • Whether the CVE-2026-85880 privilege escalation is reported working on Windows builds newer than 10 22H2 and 11 21H2.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories