Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046…
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| vendor exploited | 40 |
| public poc — 6 repositories | 20 |
| widely deployed | 15 |