Return to Threats

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

thehackernews.com 2026-09-23 malicious AI use Critical

What Happened

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

Why It Matters

The report states that China-linked threat actor UTA0565 used fake websites and a Chrome-Windows zero-day chain involving CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to deploy the previously undocumented CLEANGULP malware. The reported activity is conventional cyber-enabled malware deployment and does not establish the use of artificial intelligence. RealGround analysis: it is therefore only indirectly relevant to AI security, but the exploit-chain, phishing, and malware-delivery techniques may inform defensive threat modeling and continuous red-team scenarios for AI-enabled environments.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html

Talk to AI CISO