AI Weekly Malaysia

Back to items Summaries

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

ID
27633
Status
summarized
Published
23 Sep 2026, 4:29 PM
Fetched
23 Sep 2026, 5:39 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
23 Sep 2026, 5:40 PM
Tags
Audience
developerssaas_founders

What happened

A Chinese threat actor (UTA0565) exploited a Chrome-Windows zero-day chain (CVE-2026-85046, CVE-2026-87491 in Chrome; CVE-2026-85880 in Windows ALPC) via fake websites to break out of Chrome's sandbox and deploy CLEANGULP malware, which provides shell, process listing, file upload/download, and BOF execution. Attacks detected September 3-4, 2026 targeted Asian government entities through phishing emails impersonating NGOs and media outlets.

Why it matters

If you or your team use Chrome on Windows, patch immediately—these are sandbox-escape zero-days chained for full RCE. The attack vector is simply visiting a spoofed website, so standard phishing awareness doesn't help; browser and OS updates are the only mitigation. Builders shipping web apps should note that a malicious iframe on a lookalike domain was sufficient to trigger the exploit chain.

Discussion angle

How quickly should teams force browser/OS updates after zero-day disclosure, and what's the practical risk for non-government targets in Malaysia given the Asian government focus of this campaign?

Top