<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh" -->

---
title: Attackers are weaponizing the gap between Chromium fixes...
description: A newly documented exploit kit called BlueMoon chains three high-severity vulnerabilities—two in Chromium&#x27;s V8 JavaScript engine (CVE-2026-85046 and...
canonical: https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Attackers are weaponizing the gap between Chromium fixes and Chrome patches | daily.dev
og:description: A newly documented exploit kit called BlueMoon chains three high-severity vulnerabilities—two in Chromium&#x27;s V8 JavaScript engine (CVE-2026-85046 and...
og:url: https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh
og:image: https://api.daily.dev/og/posts/aIh4Ci2GH.png
og:image:alt: Attackers are weaponizing the gap between Chromium fixes and Chrome patches
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attackers are weaponizing the gap between Chromium fixes and Chrome patches

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 0 upvotes · 0 comments

## Summary

A newly documented exploit kit called BlueMoon chains three high-severity vulnerabilities—two in Chromium's V8 JavaScript engine (CVE-2026-85046 and CVE-2026-87491) and one Windows kernel privilege escalation flaw (CVE-2026-85880)—to give attackers full Windows admin access via a single phishing link click. Proofpoint, working with Google, Microsoft, and Volexity, found the V8 flaws were 'patch-gap' zero-days: fixed in the open-source Chromium codebase but not yet propagated to stable Chrome releases, creating a window attackers exploited using AI-accelerated reverse engineering. The kit has already spread to at least four espionage-motivated threat clusters, mostly China-nexus, targeting NGOs, mining firms, and commodity traders. Experts recommend immediate patching of Chrome and Windows, applying Proofpoint's detection rules, and rescanning for persistence artifacts since patches won't remove already-installed malware.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4220939/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches.html>

## Questions this post answers

### What is the BlueMoon exploit kit and which CVEs does it chain together?

BlueMoon is a malicious toolkit that chains three high-severity vulnerabilities: a V8 type confusion flaw (CVE-2026-85046), a V8 sandbox escape via a WebAssembly defect (CVE-2026-87491), and a Windows kernel local privilege escalation zero-day (CVE-2026-85880) affecting older builds like Windows 10 22H2 and Windows 11 21H2. Together they let attackers run code in Chrome and gain full Windows admin privileges from a single phishing link click.

_daily.dev surfaces exploit chain writeups like this so security teams can prioritize patching before attackers move first._

### What is a Chrome patch-gap zero-day and why did it happen with CVE-2026-85046?

A patch-gap zero-day occurs when a fix lands in the open-source Chromium codebase but has not yet reached stable Google Chrome releases, leaving Chrome users exposed even though the flaw is technically known and fixed upstream. CVE-2026-85046 was reported to Chromium on August 4, patched in the open-source repo, but remained exploitable in Chrome for an unusual window that attackers used to reverse-engineer a working exploit.

_Tracking patch-gap timing on daily.dev helps teams gauge real exposure windows for browser vulnerabilities._

### How should organizations respond if they suspect BlueMoon exploitation?

Patch Chrome and Windows immediately, apply Proofpoint's published detection rules, and re-scan infrastructure for artifacts like malicious Chrome extensions, scheduled tasks, or registry keys, since patching alone does not remove anything already installed by the kit. Increasing patch cadence and maintaining social-engineering awareness training are also recommended, though awareness training alone is described as an increasingly losing battle against AI-accelerated attacks.

_daily.dev helps defenders keep pace with incident response guidance as patching cadences tighten under AI-driven threats._

---

Tags: [#security](https://daily.dev/tags/security), [#windows](https://daily.dev/tags/windows), [#google-chrome](https://daily.dev/tags/google-chrome), [#chromium](https://daily.dev/tags/chromium)

[View this post on daily.dev](https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Attackers are weaponizing the gap between Chromium fixes and Chrome patches","url":"https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh"},"datePublished":"2026-09-11T01:12:57.434Z","dateModified":"2026-09-11T01:13:56.373Z","description":"A newly documented exploit kit called BlueMoon chains three high-severity vulnerabilities—two in Chromium's V8 JavaScript engine (CVE-2026-85046 and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/621e27863baefc7f7371782ca626f03f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/621e27863baefc7f7371782ca626f03f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,windows,google-chrome,chromium","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Attackers are weaponizing the gap between Chromium fixes and Chrome patches"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches-aih4ci2gh#faq","mainEntity":[{"@type":"Question","name":"What is the BlueMoon exploit kit and which CVEs does it chain together?","acceptedAnswer":{"@type":"Answer","text":"BlueMoon is a malicious toolkit that chains three high-severity vulnerabilities: a V8 type confusion flaw (CVE-2026-85046), a V8 sandbox escape via a WebAssembly defect (CVE-2026-87491), and a Windows kernel local privilege escalation zero-day (CVE-2026-85880) affecting older builds like Windows 10 22H2 and Windows 11 21H2. Together they let attackers run code in Chrome and gain full Windows admin privileges from a single phishing link click. daily.dev surfaces exploit chain writeups like this so security teams can prioritize patching before attackers move first."}},{"@type":"Question","name":"What is a Chrome patch-gap zero-day and why did it happen with CVE-2026-85046?","acceptedAnswer":{"@type":"Answer","text":"A patch-gap zero-day occurs when a fix lands in the open-source Chromium codebase but has not yet reached stable Google Chrome releases, leaving Chrome users exposed even though the flaw is technically known and fixed upstream. CVE-2026-85046 was reported to Chromium on August 4, patched in the open-source repo, but remained exploitable in Chrome for an unusual window that attackers used to reverse-engineer a working exploit. Tracking patch-gap timing on daily.dev helps teams gauge real exposure windows for browser vulnerabilities."}},{"@type":"Question","name":"How should organizations respond if they suspect BlueMoon exploitation?","acceptedAnswer":{"@type":"Answer","text":"Patch Chrome and Windows immediately, apply Proofpoint's published detection rules, and re-scan infrastructure for artifacts like malicious Chrome extensions, scheduled tasks, or registry keys, since patching alone does not remove anything already installed by the kit. Increasing patch cadence and maintaining social-engineering awareness training are also recommended, though awareness training alone is described as an increasingly losing battle against AI-accelerated attacks. daily.dev helps defenders keep pace with incident response guidance as patching cadences tighten under AI-driven threats."}}]}
```

