Urgent.News

What's breaking now, across thousands of outlets.

Tech

Multiple hacking groups found using the same Chrome malware in the same week — so what does it mean?

Someone is afraid of missing out, as defenders rush to patch things up.

Multiple hacking groups found using the same Chrome malware in the same week — so what does it mean?

Four hacking groups, including China-aligned threat actors, were observed using the same Chrome malware called BlueMoon within a single week, according to security researchers Proofpoint. BlueMoon leverages three vulnerabilities: two in Chromium and one in older versions of Windows. The Chromium vulnerabilities are in V8, the JavaScript engine used by browsers to run applications efficiently.

The first flaw, CVE-2026-85046, is a "type confusion bug" with a severity score of 8.8/10 (high), and the second is a "sandbox escape" flaw without a CVE or severity score. The Windows bug, CVE-2026-85880, is a "heap-based buffer overflow" vulnerability allowing attackers with low-privilege access to elevate privileges to SYSTEM.

Proofpoint suggests that the criminals' decision to be loud, rather than stealthy, could be due to a short window between Google patching a vulnerability and its deployment in browsers like Edge or Brave. This lack of time to hide also allows attackers to analyze Google's fixes and exploit them before browsers are patched. The recent use of AI in flaw detection has made it easier for threat actors to develop and deploy exploit kits quickly, reducing barriers to entry.

All three vulnerabilities have since been patched, so users are advised to update their operating systems and Chromium browsers to the latest versions.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 10 September →