A China-aligned threat actor tracked as UTA0565 is chaining newly disclosed Chrome and Windows zero-day vulnerabilities to deploy a novel malware family dubbed CLEANGULP.[5][6][12] The activity was observed in attacks on September 3 and 4, 2026, that used fake websites as lures to deliver the exploit chain.[5][6] The chain combined two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, with a Windows Advanced Local Procedure Call bug tracked as CVE-2026-85880 to escape the browser sandbox and achieve remote code execution.[6]
CVE-2026-85046 is a type confusion vulnerability in Chromeβs V8 JavaScript engine that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.[1][2][13] The flaw carries a CVSS v3 score of 8.8 and has been confirmed as exploited in the wild prior to Googleβs patch release.[3][13] Security advisories note that Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux contain fixes for CVE-2026-85046, with the update rolling out to users in early September 2026.[3][13] In the UTA0565 campaign, CVE-2026-85046 appears to be used inside the BlueMoon exploit kit alongside CVE-2026-87491 and CVE-2026-85880, with the final shellcode stage retrieving a file named chrome_cleanup.exe.[6]
Researchers at Volexity report that UTA0565 relies on a network of convincing clone sites, including pages spoofing news outlets, restaurant search portals and corporate training services, to funnel victims into the exploit chain.[5][12] Victims who land on these sites are served malicious HTML such as config.html, which triggers the BlueMoon kit and ultimately downloads the CLEANGULP payload from attacker-controlled infrastructure.[5][6] Analysis of infrastructure linked to the campaign identified the command-and-control domain thecovnresation[.]com, a deliberate typosquat of the legitimate media site The Conversation.[5][14][4]
CLEANGULP is described as a previously undocumented malware family written in C and compiled with Microsoft Visual C, heavily obfuscated via control-flow flattening and indirect calls to frustrate reverse engineering.[5][10][14] On infected Windows hosts, CLEANGULP installs itself as %LOCALAPPDATA%MicrosoftIMEMicrosoftIME.exe and registers a scheduled task named MicrosoftIME to maintain persistence after reboot.[5][10] The malware supports a broad command set, including running arbitrary shell commands, listing processes, uploading and downloading files, and executing beacon object files, giving operators flexible post-compromise control over compromised systems.[5][10][4]
Volexity warns that a patch gap between vendor releases and enterprise deployment windows gives actors like UTA0565 ample time to weaponize fresh bugs before defenses catch up.[5] Defenders are urged to prioritize deployment of the latest Chrome builds, verify that CVE-2026-85046 has been addressed in their environments, and monitor for suspicious scheduled tasks and binaries under the MicrosoftIME path on Windows endpoints.[1][5][13] Network teams should also watch for attempts to reach known CLEANGULP infrastructure, including traffic to domains mimicking The Conversation, and treat such activity as a likely indicator of targeted exploitation.[5][14]
With public proof-of-concept code already circulating for CVE-2026-85046 and multiple vendors tracking active exploitation, the Chrome component of this chain is poised to become a staple in broader threat activity beyond the original UTA0565 campaign.[3][7][11] Until both Chrome and Windows fixes are fully deployed, organizations in media, corporate training and other sectors seen in this campaign should assume that well-resourced adversaries are actively testing similar exploit chains against their users.[5][6][12]
References
- NVD-CVE-2026-85046
- CVE Record: CVE-2026-85046
- Google Chrome Multiple Vulnerabilities
- Chinese Hackers Use Fake Websites to Exploit Chrome and Windows Zero-Days
- Mind the (Patch) Gap, Part 2: Fake Websites Used to …
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- CVE-2026-85046 – Exploits & Severity – Feedly
- Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
- CVE-2026-85046 – High Vulnerability (PoC Available)
- Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
- Google patches actively exploited Chrome zero-day (CVE …
- Chinese APT actor uses Chrome and Windows zero-days …
