Back to all news
Security

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News·September 23, 2026·1 min read
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 exploited a Chrome-Windows zero-day chain as zero-days through fake websites, detected on September 3 and 4, 2026. The attacks chained two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) and one Windows ALPC flaw (CVE-2026-85880) to deploy CLEANGULP malware, breaking browser sandbox protections and compromising systems.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store