Live Cybersecurity News Ticker | Codekeeper

Chrome Zero-Day Exploit Spread to Four Spy Groups Within Days

Written by Content Team | Sep 10, 2026, 1:19:25 PM

A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.

The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.

Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.

TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.

Source: Cybersecurity News