Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Summary

A Chinese threat actor, UTA0565, has been exploiting a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware. The attacks, detected in early September 2026, chained two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows Advanced Local Procedure Call vulnerability (CVE-2026-85880). This exploit chain allows attackers to compromise systems through fake websites.

IFF Assessment

FOE

This article details a sophisticated exploit chain used by a threat actor to deploy malware, which is detrimental to cybersecurity defenders.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 18, 2026. Known ransomware use: Unknown.

Defender Context

This incident highlights the ongoing threat of sophisticated zero-day exploit chains, particularly those targeting widely used software like Chrome and Windows. Defenders must remain vigilant for novel attack vectors and prioritize timely patching once vulnerabilities are disclosed, as attackers are actively chaining them.

Read Full Story →