BlueMoon Campaign Exploited 27-Day Chrome Patch Gap Using AI-Assisted Tools
In September 2026, cybersecurity firm Proofpoint reported on the BlueMoon spear-phishing campaign, which exploited a Chrome V8 vulnerability tracked as CVE-2026-85046. The security fix was committed to the public Chromium repository on August 7, but the Chrome Stable channel did not ship the update until September 3, creating a 27-day window of exposure. Attackers reverse-engineered a working exploit directly from the open-source fix commit during that interval, with Proofpoint noting development patterns that suggest possible AI assistance in generating exploit variants. The gap highlights a structural issue in software supply chains, where public repositories receive fixes well before end users receive patched releases due to testing, signing, and rollout schedules. Security experts recommend monitoring security-relevant commits in deployed components rather than waiting for CVE advisories, and favoring fast-channel browser deployments to minimize exposure windows.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in