{"id":9443,"date":"2026-09-11T01:10:19","date_gmt":"2026-09-11T01:10:19","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9443"},"modified":"2026-09-11T01:10:19","modified_gmt":"2026-09-11T01:10:19","slug":"attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9443","title":{"rendered":"Attackers are weaponizing the gap between Chromium fixes and Chrome patches"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A new exploit kit is revealing the perils of the \u201cpatch later\u201d mentality.<\/p>\n<p class=\"wp-block-paragraph\">According to the <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit\" target=\"_blank\" rel=\"noopener\">Proofpoint Threat Research team<\/a>, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns.<\/p>\n<p class=\"wp-block-paragraph\">Proofpoint, which researched the new attack method along with Google\u2019s Threat Intelligence Group, Microsoft\u2019s Threat Intelligence Center, and cybersecurity company Volexity, has dubbed it BlueMoon.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals,\u201d Proofpoint noted. It offers a low cost and low barrier to entry for attackers who are increasingly <a href=\"https:\/\/www.csoonline.com\/article\/4218433\/what-do-cisos-need-to-rest-easy-about-future-ai-risks.html\" target=\"_blank\" rel=\"noopener\">using AI agents to enhance their tradecraft<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">The BlueMoon attack chain<\/h2>\n<p class=\"wp-block-paragraph\">BlueMoon strings together three different flaws in Chrome and Chromium-based browsers: A type confusion vulnerability (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-85046\" target=\"_blank\" rel=\"noopener\">CVE-2026-85046<\/a>) in Chromium\u2019s open-source V8 JavaScript engine; a V8 sandbox escape (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-87491\" target=\"_blank\" rel=\"noopener\">CVE-2026-87491<\/a>) due to a WebAssembly defect; and a Windows kernel Local Privilege Escalation (LPE) zero-day found in older Windows builds (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-85880\" target=\"_blank\" rel=\"noopener\">CVE-2026-85880<\/a>). All three vulnerabilities are rated high severity.<\/p>\n<p class=\"wp-block-paragraph\">Chaining CVE-2026-85046 and CVE-2026-87491 essentially allows attackers to run arbitrary code inside Chrome via a click on a phishing link, explained <a href=\"https:\/\/www.infotech.com\/profiles\/seva-ioussoufovitch\" target=\"_blank\" rel=\"noopener\">Seva Ioussoufovitch<\/a>, senior research analyst at Info-Tech Research Group. Adding CVE-2026-85880 \u201cexponentially worsens the impact\u201d by leveraging a Windows kernel exploit to elevate privileges on older Windows instances (Windows 10 22H2, Windows 11 21H2).<\/p>\n<p class=\"wp-block-paragraph\">\u201cBasically, BlueMoon enables threat actors to gain full Windows admin privileges in one click, and install whatever malware they want on an endpoint,\u201d Ioussoufovitch said.<\/p>\n<p class=\"wp-block-paragraph\">Both V8 vulnerabilities are \u201cpatch-gap\u201d zero-days; they were known and fixed in public upstream source code, but remained unpatched in later stable releases of Chrome and Chromium-based browsers, Proofpoint explained.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-85046 was first reported to the Chromium project by a security researcher on August 4. A fix was added to the open source Chromium codebase, which essentially serves as the foundation for Google Chrome and Chromium-based browsers. But because the fix had not yet reached newer versions of Google Chrome, there was an \u201cunusual patch gap,\u201d the researchers said.<\/p>\n<p class=\"wp-block-paragraph\">During that window, threat actors, whose ability to build exploit kits has been \u201cwildly accelerated\u201d by AI, likely had time to reverse engineer exploits from the open source codebase and take advantage of what used to seem like a reasonable patch gap, Ioussoufovitch explained.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAttackers are acting faster, and that means each day a patch is delayed carries more risk than it used to,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Effectively, at the Chromium source level, it was an N-day vulnerability (it was known and had an available patch), but in Google Chrome, it was effectively a zero-day (previously unknown) flaw, the Proofpoint threat team pointed out, noting, \u201ca fully weaponized Chrome exploit chain has historically been a high-value, rare capability.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Building rapport to spear phish victims<\/h2>\n<p class=\"wp-block-paragraph\">In one example, a China-aligned state-sponsored threat actor used the BlueMoon kit to target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US.<\/p>\n<p class=\"wp-block-paragraph\">They launched <a href=\"https:\/\/www.csoonline.com\/article\/566789\/what-is-spear-phishing-examples-tactics-and-techniques.html\" target=\"_blank\" rel=\"noopener\">spear phishing campaigns<\/a> using a range of lures: Posing as university students interested in internships at the organization; outreach regarding upcoming conferences; and even \u201ctarget-specific rapport-building exchanges\u201d that duped some users into clicking a phishing link. If they did, they were led to an actor-controlled domain, shown a loading page for several seconds as the threat actor attempted the exploit, then were directed to legitimate websites (like GitHub).<\/p>\n<p class=\"wp-block-paragraph\">This particular campaign began on August 28, and, Proofpoint explained, \u201cwithin days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Proofpoint predicted that BlueMoon will \u201clikely proliferate further and be adopted by both espionage-motivated and financially motivated threat actors.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The fact that BlueMoon was used in four separate attack clusters makes it look \u201cless like a specialized weapon and more like reusable infrastructure,\u201d agreed <a href=\"https:\/\/www.linkedin.com\/in\/nicholas-tausek-6ab41611\" target=\"_blank\" rel=\"noopener\">Nick Tausek<\/a>, lead security automation architect at Swimlane.<\/p>\n<p class=\"wp-block-paragraph\">He pointed out that increased breadth doesn\u2019t necessarily mean attackers are stretching themselves thin. \u201cA modular exploit kit lets different groups chase different objectives without rebuilding the attack chain from scratch,\u201d he noted. Further, one exploit path can surface across industries with completely different risk profiles.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBlueMoon may cast a wide net, but defenders still need to know where it can hurt [victims] most,\u201d Tausek said.<\/p>\n<p class=\"wp-block-paragraph\">For this specific attack, the fix is straightforward, Ioussoufovitch noted: Patch Chrome and Windows immediately, apply the detection rules Proofpoint has provided, and be sure to re-scan infrastructure for any artifacts linked to the kit, because anything installed by BlueMoon, such as Chrome extensions, scheduled tasks, or registry keys, won\u2019t be removed by the patches.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMore broadly, the industry needs to remain on high alert,\u201d he said. Vendors are patching faster, and organizations need to increase their patching cadence accordingly.<\/p>\n<p class=\"wp-block-paragraph\">Since many of these attacks are still exploited through social engineering, awareness training also matters, Ioussoufovitch said. However, he acknowledged: \u201cRealistically though, the pace of AI advancement is making user awareness training a losing battle.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A new exploit kit is revealing the perils of the \u201cpatch later\u201d mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns. Proofpoint, which researched the new attack [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9444,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9443","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9443"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9443"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9443\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9444"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}