Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
A newly identified exploit kit named BlueMoon is being actively used by four espionage-motivated threat clusters, including APT31, to compromise targets by chaining vulnerabilities in Google Chrome and Microsoft Windows. The attack chain combines CVE-2026-85046 (a type confusion in the V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC) to achieve remote code execution and local privilege escalation. These are "patch-gap" zero-days, meaning the bugs were fixed in upstream Chromium code before being patched in stable browser releases. While both underlying flaws have since been addressed by Google and Microsoft, the rapid adoption of this kit by multiple state-aligned actors highlights the risk of exploiting open-source patch windows.