Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Overview
A Chinese hacking group known as UTA0565 has been exploiting a recently discovered exploit chain affecting Google Chrome and Microsoft Windows. The attacks, which took place on September 3 and 4, 2026, take advantage of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one in Windows (CVE-2026-85880). By using fake websites, the attackers are able to deploy a malware variant named CLEANGULP. This is concerning as it indicates a coordinated effort to target users of these widely-used platforms, potentially compromising sensitive information and system integrity. Users of both Chrome and Windows should be vigilant and consider updating their systems promptly to mitigate the risks associated with these vulnerabilities.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Google Chrome versions affected by CVE-2026-85046 and CVE-2026-87491; Microsoft Windows systems affected by CVE-2026-85880.
- Action Required: Users should update Google Chrome to the latest version to patch the vulnerabilities CVE-2026-85046 and CVE-2026-87491.
- Timeline: Newly disclosed
Original Article Summary
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
Impact
Google Chrome versions affected by CVE-2026-85046 and CVE-2026-87491; Microsoft Windows systems affected by CVE-2026-85880.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should update Google Chrome to the latest version to patch the vulnerabilities CVE-2026-85046 and CVE-2026-87491. For Windows, ensure that the latest security updates are applied to address CVE-2026-85880.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, CVE, Zero-day, and 5 more.