← Back to Feed

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

September 10, 2026 · Malwarebytes · Severity: HIGH

This Malwarebytes article describes the BlueMoon exploit kit that chains Chrome and Windows vulnerabilities, used by four espionage groups. Attacks start with phishing emails leading to malicious pages that exploit patched Chrome flaws and a Windows privilege escalation vulnerability. It emphasises that patching delays are dangerous because attackers quickly weaponise disclosed flaws.

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble.

Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless.

But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.

The campaign is a timely reminder that once a security flaw, or even its fix, becomes public, attackers may move faster than many users expect.

The attacks began with phishing emails. A victim who clicked a malicious link could be sent to a web page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows vulnerability to break out of the browser’s protections and gain higher privileges on the computer.

The Chrome vulnerabilities used by BlueMoon were patched in the Stable channel on September 3 and September 8, 2026. The first was already actively exploited when Google released its update. Microsoft addressed the Windows vulnerability in its September Patch Tuesday updates, by which point it was also being exploited.

CISA has since added all three flaws to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities known to have been exploited in real-world attacks.

The notable part is not just that BlueMoon exploited the flaws, but how quickly the capability appears to have spread. Publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, allowing a weaponized chain to be developed and adopted by multiple groups very quickly.

Does that mean that patches can no longer be tested before they are released to the public? No, but we may need to rethink how they are tested and deployed, because it appears some cybercriminals are effectively beta-testing the patches themselves.

The researchers also found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance. The broader concern is credible: AI tools can help attackers interpret source-code changes, write and modify code, document test results, and learn from failed attempts.

In practical terms, the gap between “a flaw is fixed upstream” and “most people are protected” may be increasingly valuable to attackers. We should try to minimize that gap.

How to stay safe

Not every security update needs to be installed the moment it appears. In organizations especially, updates may need testing, staged deployment, and contingency plans. But vulnerabilities known to be actively exploited deserve greater priority. That is precisely why CISA’s KEV catalog is so important: It helps organizations identify the vulnerabilities they should address first.

For home users:

  • Install browser and operating-system updates promptly. Use the few minutes they take to grab a drink rather than repeatedly postponing them.
  • Don’t click links in unsolicited emails.
  • Use up-to-date, real-time anti-malware protection to help catch the malware that exploit kits attempt to deliver.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Key Takeaways

  • The BlueMoon exploit kit combines Chrome and Windows vulnerabilities into a single attack chain used by four espionage groups shortly after patches were released, showing how quickly attackers weaponise flaws. The kit exploits Chrome's V8 engine and a Windows privilege escalation bug to fully compromise targets.
  • Attacks begin with phishing emails that direct victims to malicious webpages exploiting two Chrome vulnerabilities (patched September 3 and 8, 2026) and a Windows bug. The kit then breaks out of browser protections to gain higher system privileges, enabling complete device control.
  • Delaying browser and OS patches is increasingly dangerous, as BlueMoon demonstrates that exploit kits can develop and spread faster than many users update. Organisations should prioritise timely patching of both Chrome and Windows to mitigate risks from similar multi-vulnerability exploit kits.
☕ Buy a Coffee