Proofpoint Documents BlueMoon, an Exploit Kit Chaining Chrome and Windows Vulnerabilities

Proofpoint researchers observed the BlueMoon exploit kit in targeted phishing campaigns. The chain exploits Chrome/V8 flaws and Windows privilege escalation; patches are available.

BlueMoon exploit kit is a previously undocumented tool that, according to Proofpoint researchers, was used by at least four espionage-motivated clusters in targeted phishing campaigns starting August 28, 2026. The chain combines two Chrome/V8 browser vulnerabilities with local Windows privilege escalation and can download additional malware after a successful attack.

Proofpoint published its findings on September 9. Google had previously confirmed that CVE-2026-85046 was exploited in the wild and released a fix for the stable version of Chrome. The U.S. agency CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on September 4.

How the BlueMoon exploit kit works

The attack begins with a spear-phishing link. After the link is opened and the vulnerabilities are successfully exploited, BlueMoon uses the Chrome/V8 flaws CVE-2026-85046 and CVE-2026-87491, according to Proofpoint. The chain then appears to enable an escape from the browser sandbox.

Another part of the attack is the Windows vulnerability CVE-2026-85880, which is used for local privilege escalation. The combination of flaws allows attackers, after a malicious link is visited, to move from code in the browser to higher privileges in Windows and download additional malware.

  • CVE-2026-85046 is a Chrome/V8 flaw for which Google confirmed an exploit being used in the wild.
  • CVE-2026-87491 is a second Chrome/V8 vulnerability used in the observed chain.
  • CVE-2026-85880 is a local Windows privilege escalation flaw.

Chrome and Windows patches are available

Updates are available for all three vulnerabilities. Users and administrators should deploy Chrome updates released in early September 2026 and Microsoft’s September security updates addressing CVE-2026-85880. It is also important to force a browser and system restart so the patched components are actually loaded.

Because CVE-2026-85046 is listed in the CISA KEV catalog, there is evidence of its active exploitation. In addition to updating, organizations should examine workstations that may have been exposed to targeted phishing. Patching alone does not remove malware that may already have been installed on a device.

More clusters observed, tool’s origin unclear

Proofpoint said that BlueMoon was deployed by at least four espionage-motivated clusters over a short period. Researchers assess that most of them are linked to China, but this is not a publicly confirmed finding by a government agency.

It is also unknown how multiple actors obtained BlueMoon. It has not been publicly confirmed whether it is a shared tool, an exploit vendor’s product, or perhaps a leak. Proofpoint also observed artifacts that may suggest the use of AI in development, but it does not consider them convincing evidence.

The full scope of compromised organizations and the number of victims remain undisclosed. Researchers particularly highlighted the rapid deployment of a complete Chrome and Windows chain by multiple espionage actors over the course of days.

What to watch next

In the near term, it will be important to see whether CISA adds CVE-2026-87491 or CVE-2026-85880 to KEV as well. Further confirmed information may also emerge about the campaigns, affected sectors and regions, indicators of compromise, and BlueMoon’s origin and the relationships among the observed clusters.

Sources

  • Proofpoint – Primary findings on BlueMoon, observed clusters, the attack process, CVEs used, and available indicators of compromise.
  • Google Chrome Releases – Google confirms the existence of an exploit for CVE-2026-85046 in the wild and the release of a Chrome security update.
  • CISA – CISA confirms that CVE-2026-85046 was added to KEV based on evidence of active exploitation.
  • SecurityWeek – Independently summarizes Proofpoint’s findings, the deployment timeline, and patch updates.

Verified and updated: September 12, 2026 15:20

Sharing