• Sources: primary, HN item
  • Summary: Ars Technica reports that Proofpoint tracked a single Chrome and Windows exploit kit, named BlueMoon, across at least four threat groups, some of them China-aligned and state-sponsored, including TA412, which the US government indicted in 2024, and states it is unknown whether other groups also gained access. Proofpoint states the chain runs a V8 type confusion tracked as CVE-2026-85046, then a V8 sandbox escape that Google assigns no CVE to, then a Windows kernel privilege escalation tracked as CVE-2026-85880 for SYSTEM rights. Ars lists Windows 10 October 2018 Update, Windows Server 2019, Windows 10 2004, Windows Server 2022 and the initial release of Windows 11 as affected, and reports all three vulnerabilities received patches in the 24 hours before publication.
  • Why it matters: Proofpoint attributes the kit's rapid development partly to AI agents lowering the cost and barrier to entry for exploit development, and states both V8 bugs were already fixed in public Chromium source while stable Chrome and Edge still shipped the vulnerable code.
  • Follow-up: Whether the same kit appears against other Chromium downstreams that trail the stable channel.

send feedback on this story