Interestana
Home/News/Chinese Hackers Exploit Chrome-Windows Zero-Day Chain
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain

A Chinese threat actor, identified as UTA0565, has been observed exploiting a newly disclosed exploit chain involving Google Chrome and Microsoft Windows as zero-days. These attacks, detected between September 3 and September 4, 2026, utilized a sophisticated method of chaining multiple vulnerabilities to compromise target systems. The exploit chain specifically involved two vulnerabilities within Google Chrome, designated as CVE-2026-85046 and CVE-2026-87491, and a separate vulnerability affecting the Windows Advanced Local Procedure Call (ALPC) mechanism, identified as CVE-2026-85880. By chaining these vulnerabilities, the attackers were able to bypass security measures and gain unauthorized access.

The initial vector for these attacks involved the use of deceptive websites designed to lure unsuspecting users. Upon visiting these compromised or malicious sites, users would inadvertently trigger the exploit chain. The first stage of the attack targeted Google Chrome, leveraging CVE-2026-85046 and CVE-2026-87491. These vulnerabilities likely allowed for remote code execution or privilege escalation within the browser environment. Once control was established within Chrome, the attackers then pivoted to exploit the Windows ALPC vulnerability, CVE-2026-85880. This Windows-specific flaw is critical as it could enable attackers to escalate privileges to a system-level, granting them extensive control over the compromised machine.

The ultimate objective of this exploit chain was the deployment of a malware strain known as CLEANGULP. While the specific functionalities of CLEANGULP were not detailed in the initial report, its deployment signifies a significant post-exploitation phase, suggesting capabilities such as data exfiltration, further system compromise, or establishing persistent access. The use of zero-day exploits, which are previously unknown and unpatched vulnerabilities, highlights the advanced capabilities of the UTA0565 threat actor and poses a considerable risk to organizations and individuals running unpatched versions of Chrome and Windows.

This incident underscores the persistent threat posed by sophisticated nation-state-backed actors and the critical importance of timely patching and robust endpoint security solutions. The exploitation of a chain of vulnerabilities, particularly involving both a widely used browser and a core operating system component, demonstrates a high level of technical proficiency and strategic planning by the attackers. Security researchers continue to analyze the full scope of the CLEANGULP malware and the specific attack methodologies employed by UTA0565 to develop effective countermeasures and inform future security strategies.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next