Chinese Threat Actor Exploits Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor tracked as UTA0565 has been observed exploiting a chain of three zero-day vulnerabilities - two in Google Chrome and one in Microsoft Windows - to deploy CLEANGULP malware. The attacks, detected in early September 2026, targeted users visiting fake websites and leveraged the exploit chain to achieve remote code execution and malware deployment. Google and Microsoft are expected to release security updates to address the vulnerabilities CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.

