Attackers are weaponizing the gap between Chromium fixes and Chrome patches
Summary
A new exploit kit named BlueMoon has been identified by security researchers, weaponizing a chain of three vulnerabilities in Chrome/Chromium browsers and Windows. This exploit kit allows threat actors to launch targeted spear-phishing campaigns by executing arbitrary code and escalating privileges on older Windows systems.
IFF Assessment
The BlueMoon exploit kit significantly increases the attack surface and capability for threat actors by chaining together multiple high-severity vulnerabilities.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 18, 2026. Known ransomware use: Unknown.
Defender Context
This article highlights the critical importance of timely patching, especially for browser and operating system vulnerabilities. Defenders need to be aware of exploit kits that chain multiple exploits, as they can be rapidly adopted by threat actors and pose a significant risk even to systems that are only partially updated.