Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Summary
A Chinese threat actor, UTA0565, has been exploiting a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware. The attacks, detected in early September 2026, chained two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows Advanced Local Procedure Call vulnerability (CVE-2026-85880). This exploit chain allows attackers to compromise systems through fake websites.
IFF Assessment
This article details a sophisticated exploit chain used by a threat actor to deploy malware, which is detrimental to cybersecurity defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 18, 2026. Known ransomware use: Unknown.
Defender Context
This incident highlights the ongoing threat of sophisticated zero-day exploit chains, particularly those targeting widely used software like Chrome and Windows. Defenders must remain vigilant for novel attack vectors and prioritize timely patching once vulnerabilities are disclosed, as attackers are actively chaining them.