#4
The Hacker News
general
September 23, 2026 at 08:29 UTC
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
By [email protected] (The Hacker News)
AI Summary
Chinese threat actor UTA0565 exploited a chained zero-day combining two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC flaw (CVE-2026-85880) to deploy CLEANGULP malware via fake websites, with attacks detected on September 3–4, 2026. Volexity identified the group as sharing exploit kit infrastructure with multiple other Chinese threat actors. The use of browser-plus-OS exploit chains against targeted victims signals sophisticated, state-aligned offensive capability.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →