Four unrelated hacking groups, including a China-aligned unit, used the exact same Chrome exploit kit against different targets within a single week.
Proofpoint calls the kit BlueMoon. It chains two Chromium flaws in the V8 JavaScript engine (a type confusion bug, CVE-2026-85046, severity 8.8, and an unscored sandbox escape) with a Windows heap overflow, CVE-2026-85880, severity 7.8, that lets code already running in a low-privilege AppContainer jump to SYSTEM. TA412, also tracked as Violet Typhoon, used it first, on August 28, against US NGOs, mining firms, and commodity traders. Within days, three more groups followed: UNK_LateNight against US aerospace companies, UNK_DoubleCheck against a Vietnamese manufacturer, and UNK_QuietRacket across Singapore and Indonesia. All three bugs are now patched, and Proofpoint says they were patch-gap zero-days, already fixed in Chromium's public source but not yet rolled out to Chrome, Edge, or Brave users.
The real story here isn't the exploits, it's the noise. Four groups burning the same rare, fully weaponized browser chain within a week, each loudly enough to get caught, is unusual: stealth normally buys more mileage from a zero-day. Proofpoint's read is that the patch-gap window itself has become a shared resource, since anyone can reverse-engineer Google's public fix before it reaches actual browsers, leaving no reason to wait quietly. The firm also floats, more cautiously, that AI-assisted bug-hunting may be lowering the cost of turning a patch into a working exploit, though it stops short of calling that the cause.
A fully weaponized Chrome exploit chain used to be a rare, expensive thing state actors hoarded and guarded closely. Four groups grabbing the same one in the same week suggests that scarcity is eroding, patch cadence or not.