CyberSecurity News
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
AI summary
A Chinese threat actor, UTA0565, has been exploiting a zero-day chain in Google Chrome and Microsoft Windows. The exploitation involves two Chrome vulnerabilities and one Windows vulnerability, which are chained together to bypass security measures. This exploit chain is being used to deploy CLEANGULP malware through fake websites. The attacks were detected on September 3 and 4, 2026. The specific vulnerabilities being exploited are in Chrome and Windows Advanced Local Procedure Call. The threat actor is using this exploit chain to successfully break through security defenses.
Vulnerabilities mentioned
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

