CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8277

As cited

Copy frozen at (site build).

vulnerabilities

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Chinese threat actor UTA0565 exploited a chain of vulnerabilities in Google Chrome and Microsoft Windows as zero-days in early September 2026 to deploy CLEANGULP malware via fake websites. The attack leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome together with CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC) to achieve code execution.

Why it matters: Organizations running Windows and Chrome are exposed to active exploitation by a sophisticated Chinese actor using unpatched zero-day chains; patching these CVEs and validating endpoint detection and response (EDR) coverage are immediate priorities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary