HomeIntelligenceBrief
VULNERABILITY BRIEF 🟠 High ThreatIntel

Chinese Hackers Exploit Chrome‑Windows Zero‑Day Chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880) to Deploy CLEANGULP Malware

A Chinese threat actor (UTA0565) chained two Chrome and one Windows zero‑day vulnerabilities to deliver CLEANGULP malware via malicious web pages. The campaign underscores the need for rapid patching and continuous control evidence to satisfy audit and compliance requirements.

Verisq™ Intelligence · 📅 September 23, 2026 · 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
thehackernews.com

Chinese Hackers Exploit Chrome‑Windows Zero‑Day Chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880) to Deploy CLEANGULP Malware

What It Is — A Chinese threat group (UTA0565) leveraged a newly disclosed exploit chain that combines two Chrome browser flaws (CVE‑2026‑85046, CVE‑2026‑87491) with a Windows Advanced Local Procedure Call vulnerability (CVE‑2026‑85880). The chain is used to deliver the CLEANGULP malware via malicious web pages.

Exploitability — The vulnerabilities have been observed in the wild (attacks on Sep 3‑4 2026). No public proof‑of‑concept exists beyond the reported campaign, but the active exploitation indicates a high likelihood of successful compromise.

Affected Products — Google Chrome (all supported versions at the time of disclosure) and Microsoft Windows (versions supporting the ALPC component).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability monitoring and rapid patch deployment as a core control for maintaining a defensible audit trail.
  • Highlights the importance of mapping identified gaps to a unified control framework (VCF) so evidence can be presented across multiple compliance regimes.
  • Shows that endpoint detection must be tied to evidence‑collection processes that can be surfaced in a Trust Center for stakeholder assurance.

Recommended Actions

  1. Inventory all Chrome browsers and Windows endpoints; verify they are running versions patched for CVE‑2026‑85046, CVE‑2026‑87491, and CVE‑2026‑85880.
  2. Apply the latest security updates from Google and Microsoft immediately.
  3. Deploy detection signatures for CLEANGULP and monitor logs for anomalous ALPC activity.
  4. Conduct a focused vulnerability scan on web‑facing assets to ensure no residual exposure.
  5. Document remediation steps and map the patched controls to your framework of record for audit readiness.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →