China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
- ID
- 24568
- Status
- summarized
- Published
- 15 Sep 2026, 1:31 PM
- Fetched
- 15 Sep 2026, 3:13 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 15 Sep 2026, 3:13 PM
- Tags
- Audience
- developersvibe_coders
What happened
Volexity attributes a spear-phishing campaign targeting NGOs to Chinese threat actor UTA0560, which chained three patched zero-days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) across Chrome's V8 sandbox and Windows ALPC to deploy a JavaScript backdoor called GRIMWEDGE. The attack used a reflected XSS on a U.S. university website as the entry point, filtered for Chrome-on-Windows visitors, and delivered Base64-encoded shellcode payloads via a multi-stage exploit chain dubbed BlueMoon.
Why it matters
All three CVEs are already patched, so the actionable takeaway is narrow: ensure Chrome and Windows are updated in your environment, and treat reflected XSS on legitimate sites as a real attack vector rather than a low-priority finding. For builders running web apps that accept user input, this is a concrete reminder that an XSS on your site can be the pivot point for a nation-state exploit chain, not just a defacement risk.
Discussion angle
How a single reflected XSS on a university website became the delivery mechanism for a three-stage zero-day chain — and whether your team's XSS findings are being triaged with that severity in mind.