AI Weekly Malaysia

Back to items Summaries

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

ID
24568
Status
summarized
Published
15 Sep 2026, 1:31 PM
Fetched
15 Sep 2026, 3:13 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
15 Sep 2026, 3:13 PM
Tags
Audience
developersvibe_coders

What happened

Volexity attributes a spear-phishing campaign targeting NGOs to Chinese threat actor UTA0560, which chained three patched zero-days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) across Chrome's V8 sandbox and Windows ALPC to deploy a JavaScript backdoor called GRIMWEDGE. The attack used a reflected XSS on a U.S. university website as the entry point, filtered for Chrome-on-Windows visitors, and delivered Base64-encoded shellcode payloads via a multi-stage exploit chain dubbed BlueMoon.

Why it matters

All three CVEs are already patched, so the actionable takeaway is narrow: ensure Chrome and Windows are updated in your environment, and treat reflected XSS on legitimate sites as a real attack vector rather than a low-priority finding. For builders running web apps that accept user input, this is a concrete reminder that an XSS on your site can be the pivot point for a nation-state exploit chain, not just a defacement risk.

Discussion angle

How a single reflected XSS on a university website became the delivery mechanism for a three-stage zero-day chain — and whether your team's XSS findings are being triaged with that severity in mind.

Top