Chrome Zero-Day: The BlueMoon Exploit Chain and Your Business Security
All dispatches
Security18 Sept 20266 min read

Chrome Zero-Day: The BlueMoon Exploit Chain and Your Business Security

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

Google has issued an emergency update for Chrome to fix the seventh Chrome zero-day vulnerability discovered in 2026. This specific flaw, tracked as CVE-2026-87491, is not a theoretical risk. It is currently being used by state-aligned threat actors to bypass browser security and install malware on Windows machines. If your team uses Chrome and has not restarted their browsers since 9 September 2026, your business remains exposed to a highly sophisticated exploit chain known as BlueMoon.

This incident highlights a growing trend where attackers no longer rely on a single mistake. Instead, they link multiple vulnerabilities together to create a path from a simple website visit to a full network compromise. For a UK SME, the distance between a member of staff clicking a link and a ransomware actor sitting on your server has become uncomfortably short.

The mechanics of the BlueMoon exploit kit

The BlueMoon exploit kit is a package of malicious code designed to find and use specific weaknesses in a computer's software. In this instance, it targets a vulnerability in the V8 engine, which is the component of Chrome responsible for executing JavaScript (the code that makes modern websites interactive). When the V8 engine has a flaw like CVE-2026-87491, it allows an attacker to perform what is known as 'arbitrary code execution'.

In plain words, this means the attacker can force your browser to run their own commands instead of the website's legitimate code. Usually, browsers live in a 'sandbox', which is a restricted environment that prevents the browser from talking to the rest of your computer. However, the BlueMoon kit chains this Chrome flaw with a separate Windows vulnerability to 'escape' that sandbox. Once they are out, they deploy a payload called GRIMWEDGE, a type of malware designed to steal credentials and provide long-term access to your business network.

Calculating the cost of a hijacked browser

It is tempting to view a browser update as a minor inconvenience, but the financial reality of a successful exploit is significant. Consider a 40-person UK accountancy firm. If a single partner's browser is compromised via the BlueMoon kit, and that leads to a ransomware deployment, the clock starts ticking immediately.

If the firm faces 12 hours of total downtime while systems are wiped and restored from backups, and we assume an average billable rate or productivity value of £150 per hour per staff member, the direct labour loss is £72,000. This does not include the cost of a forensic IT investigation (often starting at £5,000), potential ICO fines for data breaches, or the subsequent increase in cyber insurance premiums. A five-minute browser restart is a very cheap alternative to a £80,000 week.

A pattern we see on most tenants we take on

A pattern we see on most tenants we take on is that while Windows updates are managed centrally, browser updates are frequently left to chance. We often find workstations that have been active for weeks with a 'Update' button glowing in the corner of the browser, ignored by a busy user. This creates a window of vulnerability that stays open long after a patch is released. In a managed environment, these updates should be forced, not requested.

How to verify your Chrome version today

You can check if your team is protected by looking at the version number of Google Chrome. The fix is included in versions 153.0.7044.110 and later for Windows and Mac.

To check your version, click the three vertical dots in the top right corner of Chrome, select 'Help', and then 'About Google Chrome'. The browser will automatically check for updates on this screen. If it finds one, it will download it, but it will not be applied until the browser is fully closed and reopened. This is the step most users miss: they 'close' the window but leave the application running in the background, keeping the vulnerability active.

The regulatory and compliance dimension

For businesses working towards or maintaining Cyber Essentials, the rules are clear. Critical security updates must be applied within 14 days of release. Because CVE-2026-87491 is a zero-day being exploited in the wild, it is classified as critical. Failing to update your fleet of devices within this window technically puts you out of compliance.

Beyond certification, the Information Commissioner’s Office (ICO) looks unfavourably on organisations that suffer a data breach through 'known and patchable' vulnerabilities. If a China-linked threat actor steals your client data via a browser flaw that had a fix available for two weeks, 'we forgot to restart the browser' is not a valid legal defence under UK GDPR.

Practical actions for the next 24 hours

  1. Force a restart: Instruct all staff to completely shut down and restart Chrome. A full machine reboot is even better to ensure any pending Windows patches are also applied.
  2. Audit your versions: If you use a device management tool, run a report to see which machines are still on versions older than 153.0.7044.110.
  3. Check for Edge: Remember that Microsoft Edge is built on the same 'Chromium' foundation. If there is a Chrome zero-day, there is almost certainly a corresponding Edge update that needs to be applied.
  4. Review user permissions: Ensure users do not have local admin rights. The BlueMoon kit is much harder to execute if the user account it infects doesn't have the permission to install new software or change system settings.

Staying ahead of the next zero-day

This is the sixth and seventh time this year that Google has had to scramble to fix a flaw that was already being used by criminals. This is the new normal. Security is no longer about building a wall and leaving it; it is about the speed of your response. If your IT setup relies on users making the right choice about when to update, you are effectively outsourcing your cyber security to your most distracted employee.

How Black Sheep Support secures your team

We don't leave browser security to chance. We manage the update cycle for our clients, ensuring that critical patches for Chrome, Edge, and Windows are deployed and enforced without requiring user intervention. This closes the 'vulnerability window' from weeks to hours.

If you are worried that your current IT setup is leaving gaps for exploit kits like BlueMoon

Book a Discovery Call

and we'll look at your current update policies and show you how to automate your defence. We also handle hardware, broadband, mobile and networking, providing a complete IT department for UK SMEs.

Not ready to talk yet? Run our free IT Health Check to assess your business risk and security posture in minutes, no commitment.

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.