ZeroHour
Story · 8 sources · 8 articlesfirst updated ()

BlueMoon exploit kit chains Chrome V8 and Windows ALPC zero-days; China-linked espionage groups deploy GRIMWEDGE and LONGTALE

What's new: Initial merged summary covering reporting from September 10–15, 2026. September 10: BleepingComputer and Malwarebytes Labs revealed the shared BlueMoon kit, four activity clusters, the September 3 and 8 Chrome Stable patches, and CISA KEV listings for all three CVEs. September 11: CSO Online added the multi-vendor collaboration (Google Threat Intelligence Group, MSTIC, Volexity), the…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Multiple mostly China-linked espionage clusters share the BlueMoon exploit kit, which chains Chrome V8 zero-days CVE-2026-85046 and CVE-2026-87491 with Windows ALPC privilege escalation zero-day CVE-2026-85880 to go from a single phishing click to full admin…

Proofpoint, working with Google Threat Intelligence Group, Microsoft Threat Intelligence Center and Volexity, identified BlueMoon, a shared exploit kit chaining two Chrome V8 zero-days — CVE-2026-85046 (V8 type confusion) and CVE-2026-87491 (described variously as a V8 or WebAssembly sandbox escape) — with CVE-2026-85880, a Windows ALPC/kernel privilege escalation in RtlpCreateServerAcl. All three are rated high severity, were actively exploited, and were added to CISA's KEV catalog. The kit exploits an unusual patch gap: fixes landed in upstream Chromium source (after private reporting in August) but had not shipped in Chrome Stable, which released patches on September 3 and 8, 2026; BlueMoon's maintainers reverse-engineer public Chromium fixes before stable releases. The Windows fix arrived in September Patch Tuesday (cumulative KB5124008, September 8). Proofpoint first observed the kit on August 28, 2026, used by JungleBamboo (APT31) — named Violet Typhoon (APT31) by SecurityWeek — against a small number of US NGOs and mining/commodity trading firms; three further clusters (UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) adopted it within days against US aerospace/defense, Vietnamese manufacturers, and targets in the US, Vietnam, Indonesia and Singapore, including aerospace, manufacturing, government and finance. Volexity documented campaigns detected September 1 in which UTA0560 and JungleBamboo ran byte-identical chains delivered via reflected-XSS links on legitimate US university sites and hidden iframes behind a donation-form image: UTA0560 deployed the in-memory GRIMWEDGE JScript backdoor, while JungleBamboo used the SUPERSTOMP loader to install LONGTALE/GemStone, a credential-stealing Chrome extension disguised as Google Gemini. Clues, but no conclusive evidence, suggest the kit was built with AI assistance. Separately, the mandatory KB5124008 update for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445) breaks certificate-based Always On VPN on some enterprise clients, forcing some admins to pause VPN cohorts while still patching the exploited zero-days.

  • BlueMoon chains CVE-2026-85046 (Chrome V8 type confusion), CVE-2026-87491 (V8 sandbox escape; some sources describe it as a WebAssembly sandbox escape) and CVE-2026-85880 (Windows ALPC/kernel local privilege escalation in…
  • Patch gap: V8 fixes existed in upstream Chromium source (after private reporting in August 2026) but had not reached Chrome Stable; the Chrome flaws were patched in Stable on September 3 and 8, 2026, and CVE-2026-85880 was fixed in…
  • BlueMoon's maintainers reverse-engineer public Chromium fixes before stable Chrome releases to build exploits; the kit fingerprints the host, uses the V8 flaws for sandbox escape, injects a CreateProcess stub into the Chrome broker process…
  • Proofpoint first observed the kit on August 28, 2026, used by JungleBamboo (APT31) per BleepingComputer's report of Proofpoint findings; SecurityWeek names the same APT31-tracked actor Violet Typhoon — the sources disagree on the actor…
  • Targets of the August 28 actor were a small number of US NGOs and mining and commodity trading firms, approached with internship, conference and rapport-building spear-phishing lures.
  • Three more espionage clusters adopted BlueMoon within days: UNK_LateNight (US aerospace/defense, deploying ShadowPad), UNK_DoubleCheck (Vietnamese manufacturers) and UNK_QuietRacket; SecurityWeek lists targets in the US, Vietnam, Indonesia…
  • Volexity documented campaigns detected September 1, 2026, in which UTA0560 and JungleBamboo (APT31) ran byte-identical exploit shellcode; Volexity assesses — with confidence reported as medium by GBHackers and low by Security Affairs —…
  • Delivery path seen by Volexity: links on legitimate US university sites vulnerable to reflected XSS redirected victims to attacker pages serving hidden exploit iframes behind a donation-form image.

Coverage timeline

  1. · 7d ago
    BleepingComputer· 85
    New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple China-linked espionage groups share the BlueMoon exploit kit chaining Chrome V8 zero-days and a Windows ALPC LPE to deploy backdoors.

  2. · 6d ago
    Malwarebytes Labs· 75
    BlueMoon exploit kit turns Chrome and Windows flaws into attacks

    Proofpoint documents BlueMoon exploit kit used by four espionage groups to chain Chrome V8 and Windows flaws via phishing, all now in CISA's KEV.

  3. · 6d ago
    CSO Online· 82
    Attackers are weaponizing the gap between Chromium fixes and Chrome patches

    Espionage actors use the BlueMoon exploit kit to chain Chrome V8 and Windows kernel zero-days via spear phishing, gaining full admin on unpatched endpoints.

  4. · 6d ago
    Cyber Security News· 48
    Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

    Microsoft's September 2026 Windows 11 update KB5124008 breaks certificate-based Always On VPN on some enterprise clients, forcing admins to pause rollout.

  5. · 5d ago
    GBHackers· 85
    China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

    Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs.

  6. · 5d ago
    SecurityWeek· 88
    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Proofpoint reports multiple espionage groups rapidly adopting BlueMoon, a new exploit kit chaining Chrome and Windows zero-days.

  7. · 2d ago
    The Hacker News· 85
    China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    Volexity attributes spear-phishing campaign exploiting Chrome-Windows zero-day chain to Chinese actors UTA0560 and APT31 deploying GRIMWEDGE and LONGTALE.

  8. · 2d ago
    Security Affairs· 85
    One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

    Two China-linked APT groups reused identical Chrome/Windows zero-day chain against NGOs, deploying GRIMWIDGE backdoor and LONGTALE credential-stealing extension.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81963
+1 in the same advisory: …85880
Local Privilege Escalation via Link Following in Windows Update Stack

CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.

Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems.

7.8<1% KEV
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2025
masswell over 1,000,000
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)