A new exploit kit named BlueMoon has emerged, exploiting Chrome and Windows flaws in quick succession and illustrating the risks of patch-timing in the wild. The campaign began with phishing emails that directed victims to a page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows privilege-escalation flaw to break out of the browser’s protections.
Security researchers say four espionage groups used the same exploit chain against Chrome on Windows within days of one another, underscoring how rapidly attackers can weaponise fixes once details become public.
Chromium and Windows updates were released in early September 2026, with the two Chrome flaws patched on 3 September and 8 September, and the Windows vulnerability addressed during Microsoft’s September Patch Tuesday. By that point, all three flaws were already being exploited in the wild, and CISA subsequently added them to the Known Exploited Vulnerabilities (KEV) catalog.
The rapid spread of BlueMoon demonstrates that publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, enabling multiple actor groups to adopt a weaponised chain quickly. Researchers have flagged faint indications that the exploit kit may have been developed with AI assistance, though there is no conclusive evidence.
In practical terms, the report cautions that organisations should reassess how patches are tested and deployed, recognising a potential growing window between upstream fixes and broad user protection. For home users, the guidance centres on installing updates promptly, avoiding phishing links, and maintaining current anti-malware protection.