Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Reported exploitedChromeUTA0565WindowsOur summary
Chinese-linked actor UTA0565 used fake websites to exploit a zero-day chain affecting Google Chrome and Microsoft Windows: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The flaws enabled a browser sandbox escape and remote code execution, delivering the CLEANGULP malware, which can run commands, manage files, inspect processes, and execute BOF payloads.
Read at The Hacker News
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.