Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
- ID
- 22918
- Status
- summarized
- Published
- 10 Sep 2026, 12:34 AM
- Fetched
- 10 Sep 2026, 4:19 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 10 Sep 2026, 4:20 AM
- Tags
- Audience
- developerssaas_founders
What happened
Proofpoint reports that four espionage-motivated threat clusters used a previously undocumented exploit kit called BlueMoon within days of each other starting August 28, 2026. The kit chains CVE-2026-85046 (V8 type confusion in Chrome), an unassigned V8 sandbox escape, and CVE-2026-85880 (Windows ALPC heap overflow), with both V8 bugs being 'patch-gap' zero-days—already fixed in upstream Chromium source but not yet in stable Chrome releases.
Why it matters
If you ship Electron, Chromium-embedded, or any Chromium-based browser product, the patch-gap pattern here is the actionable detail: upstream Chromium fixes can lag behind stable releases, and exploit developers are actively monitoring those public patches to build chains before they reach your users. Consider tracking Chromium security commits directly rather than waiting for stable-channel patch notes, and push updates promptly when V8 fixes land upstream.
Discussion angle
The patch-gap problem: how upstream-open security fixes in Chromium create a window where exploit developers can reverse-engineer patches before stable releases ship—does your team track upstream commits or only stable CVE announcements?