Proofpoint Tracks BlueMoon Kit Chaining Two Chromium CVEs and Windows Kernel Flaw Across Four Actors
BlueMoon demonstrates rapid weaponization and sharing of a full browser-to-kernel chain enabled by public Chromium patch diffs and AI-assisted reverse engineering. The 24-hour deployment window across multiple actors marks a measurable drop in capability cost. Operational impact depends on downstream browser and OS update velocity.
Proofpoint researchers documented identical BlueMoon payloads used by four distinct clusters, including actors with reported Chinese government links. The kit chains two Chromium remote code execution flaws with a Windows kernel elevation vulnerability affecting Windows 10 October 2018 Update through initial Windows 11 releases. All three vulnerabilities received patches in the preceding 24 hours. Targets spanned government, enterprise, and technology organizations without observed targeting filters.
Google: 85% of Chrome stable instances will incorporate the relevant patches within 96 hours, measured by telemetry on September 15 2026.
Sources (3)
- [1]Proofpoint Threat Insight: BlueMoon Exploit Kit Analysis(https://www.proofpoint.com/us/threat-insight/post/bluemoon)
- [2]Chromium Security: Stable Channel Update(https://chromereleases.googleblog.com/2026/09/stable-channel-update.html)
- [3]Microsoft Security Response Center: September 2026 Patch Tuesday(https://msrc.microsoft.com/update-guide)