ZeroHour
Story · 1 source · 1 articlefirst updated ()1

BlueMoon exploit kit chains Chrome and Windows zero-days across China-linked espionage groups as patches land — but the Windows update breaks Always On VPN

What's new: Compared with the previous story summary (2026-09-17), this merge adds: the previously missing CVE ids for the BlueMoon chain — CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880 — resolving the prior caveat and confirming CVE-2026-87491 is one of the two BlueMoon Chrome V8 flaws; identification of the Windows fix as the September 8, 2026 KB5124008, which also patches a second actively exploited…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Proofpoint and Volexity report that multiple China-linked espionage clusters shared the BlueMoon exploit kit, chaining Chrome V8 zero-days CVE-2026-85046 and CVE-2026-87491 with Windows privilege-escalation zero-day CVE-2026-85880; fixes shipped in Chrome…

Google's Chrome stable channel update 153.0.8010.36/.37 for Windows and Mac (153.0.8010.36 for Linux) fixes 230 flaws, including five Critical (four of them in WebGL), among them the actively exploited V8 flaw CVE-2026-87491. Google rates it medium severity; Malwarebytes describes it as an out-of-bounds write that a crafted HTML page can use to run code inside the browser sandbox, while Proofpoint/Volexity reporting describes it as a V8/WebAssembly sandbox escape. The two BlueMoon Chrome V8 flaws were patched in Chrome Stable on September 3 and 8, 2026; the Windows flaw CVE-2026-85880 was fixed in the September 8 Patch Tuesday cumulative update KB5124008, which also fixes a second actively exploited zero-day, CVE-2026-81963 in the Windows Update Stack. All three BlueMoon flaws were actively exploited and added to CISA's KEV catalog. The V8 fixes had landed in upstream Chromium source after private August reporting but had not yet reached Chrome stable, a patch gap the attackers reverse-engineered and weaponized. Proofpoint, working with Google Threat Intelligence Group, Microsoft Threat Intelligence Center and Volexity, reports that BlueMoon chains CVE-2026-85046 (V8 type confusion), CVE-2026-87491 and CVE-2026-85880 (a Windows ALPC/kernel privilege escalation, located in RtlpCreateServerAcl per Volexity; CSO Online rates all three high severity). The kit fingerprints the host and injects a CreateProcess stub into the Chrome broker process to download and execute a payload via curl, yielding full Windows admin from a single phishing click. Proofpoint observed first use on August 28, 2026 by APT31 — called JungleBamboo in most reports and Violet Typhoon by SecurityWeek — against US NGOs and mining/commodity-trading firms using internship, conference and rapport-building spear-phishing lures. Three more mostly China-linked clusters adopted it within days: UNK_LateNight (US aerospace/defense, deploying ShadowPad), UNK_DoubleCheck (Vietnamese manufacturers) and UNK_QuietRacket (per SecurityWeek, hitting government and finance across the US, Vietnam, Indonesia and Singapore); BleepingComputer instead lists UTA0560 among the four clusters. Other payloads include loaders, Grimwedge and an in-memory Rust loader. Proofpoint suspects the ALPC exploit has existed since 2025 and found clues, but no conclusive evidence, of AI-assisted kit development. IOCs are published by Proofpoint and Volexity, with broader — possibly criminal or financially motivated — adoption…

  • Chrome stable 153.0.8010.36/.37 (Windows/Mac) and 153.0.8010.36 (Linux) ship 230 fixes, including five Critical — four of them in WebGL.
  • BlueMoon chains CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 out-of-bounds write / sandbox escape) and CVE-2026-85880 (Windows ALPC/kernel privilege escalation, in RtlpCreateServerAcl per Volexity).
  • Severity is disputed: Google rates CVE-2026-87491 medium, while CSO Online describes all three BlueMoon flaws as high severity.
  • The two Chrome flaws were patched in Chrome Stable on September 3 and 8, 2026; CVE-2026-85880 was fixed in the September 8, 2026 Patch Tuesday cumulative update KB5124008.
  • All three BlueMoon flaws were actively exploited and added to CISA's KEV catalog.
  • KB5124008 for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445) also fixes a second actively exploited zero-day, CVE-2026-81963 in the Windows Update Stack.
  • Proofpoint observed BlueMoon first used August 28, 2026 by APT31 (JungleBamboo; SecurityWeek calls it Violet Typhoon) against US NGOs and mining/commodity-trading firms via internship, conference and rapport-building spear-phishing lures.
  • Three further clusters adopted it within days: UNK_LateNight (US aerospace/defense, ShadowPad), UNK_DoubleCheck (Vietnamese manufacturers) and UNK_QuietRacket (per SecurityWeek); BleepingComputer instead lists UTA0560 among the four…

Coverage timeline

  1. · 7d ago
    Malwarebytes Labs· 75
    Update Chrome now to protect against an actively exploited vulnerability

    Google shipped Chrome 153.0.8010.36/.37 fixing 230 flaws including actively exploited V8 out-of-bounds write CVE-2026-87491 enabling sandboxed code execution.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81963
+1 in the same advisory: …85880
Local Privilege Escalation via Link Following in Windows Update Stack

CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.

Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems.

7.8<1% KEV
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2025
masswell over 1,000,000
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)