How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491

Key Takeaways

  • BlueMoon Exploit Kit, first observed on August 28, 2026, turns visits to malicious websites into Windows malware execution.
  • The kit chains two V8 vulnerabilities with a Windows kernel exploit to run payloads outside the browser sandbox.
  • CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 enable V8 type confusion, sandbox escape, and kernel privilege escalation respectively.
  • Spearphishing emails lead victims to attacker-controlled exploit pages, some of which then redirect to legitimate websites.
  • Four espionage-focused threat clusters adopted BlueMoon to deliver GemStone, ShadowPad, a Rust loader, and custom .NET-staged malware.
  • The Picus Threat Library includes BlueMoon-related threats for testing defenses against V8 exploits and GemStone malware.

BlueMoon Exploit Kit is a malware delivery kit first observed on August 28, 2026. Campaigns targeted the US and Southeast Asia, including Vietnam, Indonesia, and Singapore, across nonprofit, mining, commodity trading, aerospace, manufacturing, government, consulting, and financial sectors [1].

Article Link: How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491