Home / Sep 24, 2026 / Story
0
#4 The Hacker News general September 23, 2026 at 08:29 UTC

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

By [email protected] (The Hacker News)

AI Summary

Chinese threat actor UTA0565 exploited a chained zero-day combining two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC flaw (CVE-2026-85880) to deploy CLEANGULP malware via fake websites, with attacks detected on September 3–4, 2026. Volexity identified the group as sharing exploit kit infrastructure with multiple other Chinese threat actors. The use of browser-plus-OS exploit chains against targeted victims signals sophisticated, state-aligned offensive capability.

Relevance score: 87.0/100

# More from September 24