At least four espionage crews, most with suspected links to China, are using the same new exploit kit to break into networks in the US and Southeast Asia. Proofpoint named the kit BlueMoon and said it chains three flaws in Chrome and Windows.
Two are V8 bugs in Chromium-based browsers: CVE-2026-85046, a type confusion, and CVE-2026-87491, an out-of-bounds flaw that escapes the browser sandbox. The third, CVE-2026-85880, is a heap overflow in Windows Advanced Local Procedure Call that lifts a renderer to system privileges.
The first use came on August 28 from APT31, also tracked as Violet Typhoon and TA412, a group US prosecutors tie to China’s Ministry of State Security. It used phishing to target non-governmental organizations, mining companies and commodity trading firms. Within days, other clusters picked up the kit. Proofpoint logged fewer than 20 victims worldwide but expects the true figure to be higher, and said the activity is ongoing.
Both V8 bugs were patch-gap zero-days. They were fixed in the upstream Chromium source but had not reached stable browser releases, giving whoever built the kit a window to reverse the fixes. Google patched CVE-2026-87491 on September 8. Microsoft closed the Windows bug on Patch Tuesday.
