Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- ID
- 27633
- Status
- summarized
- Published
- 23 Sep 2026, 4:29 PM
- Fetched
- 23 Sep 2026, 5:39 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 23 Sep 2026, 5:40 PM
- Tags
- Audience
- developerssaas_founders
What happened
A Chinese threat actor (UTA0565) exploited a Chrome-Windows zero-day chain (CVE-2026-85046, CVE-2026-87491 in Chrome; CVE-2026-85880 in Windows ALPC) via fake websites to break out of Chrome's sandbox and deploy CLEANGULP malware, which provides shell, process listing, file upload/download, and BOF execution. Attacks detected September 3-4, 2026 targeted Asian government entities through phishing emails impersonating NGOs and media outlets.
Why it matters
If you or your team use Chrome on Windows, patch immediately—these are sandbox-escape zero-days chained for full RCE. The attack vector is simply visiting a spoofed website, so standard phishing awareness doesn't help; browser and OS updates are the only mitigation. Builders shipping web apps should note that a malicious iframe on a lookalike domain was sufficient to trigger the exploit chain.
Discussion angle
How quickly should teams force browser/OS updates after zero-day disclosure, and what's the practical risk for non-government targets in Malaysia given the Asian government focus of this campaign?