# Chinese Threat Actor UTA0565 Weaponizes Chrome-Windows Zero-Day Chain Against Users
A Chinese threat actor tracked as UTA0565 has begun exploiting a chained set of zero-day vulnerabilities spanning Google Chrome and Microsoft Windows to deliver the CLEANGULP malware. Security researchers detected the active exploitation on September 3 and 4, 2026, deployed through deceptive websites designed to trick users into visiting malicious pages.
The attack chain leverages three distinct vulnerabilities. Two reside in Google Chrome: CVE-2026-85046 and CVE-2026-87491. The third, CVE-2026-85880, affects Windows Advanced Local Procedure Call (ALPC), a core inter-process communication mechanism in the Windows kernel. By chaining these flaws together, UTA0565 bypasses multiple layers of security controls that would typically isolate compromised browser processes from the operating system itself.
The exploitation sequence works this way. A user visits a fraudulent website hosted or controlled by the attacker. Chrome processes malicious content and triggers the first vulnerability. This plants a foothold within the browser sandbox. The second Chrome vulnerability then escalates privileges within that sandbox environment, breaking the isolation that normally prevents browser code from accessing system resources. Finally, the attacker leverages CVE-2026-85880 to escape the browser entirely and gain arbitrary code execution at the kernel level. At that point, CLEANGULP malware executes with system privileges, giving the attacker complete control over the target machine.
CLEANGULP remains a poorly documented malware family. Its functionality and payload capabilities have not been fully disclosed in public reporting, though the fact that UTA0565 invested in a complex three-stage exploit chain suggests the malware performs objectives that demand elevated system access. Possible uses include credential theft, persistent backdoor installation, data exfiltration, or lateral movement preparation within corporate networks.
UTA0565 operates as part of the broader Chinese state-sponsored threat landscape. The group has conducted espionage campaigns targeting government agencies, technology firms, and critical infrastructure operators across Asia-Pacific and North America. This latest activity aligns with UTA0565's known tactics of weaponizing newly disclosed vulnerabilities faster than defenders can patch them.
The timing matters. Chrome CVE-2026-85046 and CVE-2026-87491 appear to have been disclosed recently enough that many systems remained unpatched when UTA0565 launched attacks. Windows CVE-2026-85880 similarly likely had limited patch adoption at the time of exploitation. This window, typically measured in hours or days after disclosure, represents peak risk for zero-day chains.
Organisations should immediately prioritize patching all three vulnerabilities across their infrastructure. Chrome users must update to the latest available version. Windows administrators should deploy CVE-2026-85880 patches without delay. Web filtering and intrusion prevention systems require immediate rule updates to block traffic to known malicious domains associated with this campaign.
Users should avoid clicking links from untrusted sources and disable auto-update delays in Chrome where possible. Security teams should assume breach and conduct forensics on systems that visited suspicious websites between September 3 and 4, 2026, or thereafter until the campaign was disrupted.
