Chrome and Windows zero-days power CLEANGULP attacks

A China-aligned threat actor tracked as UTA0565 is chaining newly disclosed Chrome and Windows zero-day vulnerabilities to deploy a novel malware family dubbed CLEANGULP.[5][6][12] The activity was observed in attacks on September 3 and 4, 2026, that used fake websites as lures to deliver the exploit chain.[5][6] The chain combined two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, with a Windows Advanced Local Procedure Call bug tracked as CVE-2026-85880 to escape the browser sandbox and achieve remote code execution.[6]

CVE-2026-85046 is a type confusion vulnerability in Chrome’s V8 JavaScript engine that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.[1][2][13] The flaw carries a CVSS v3 score of 8.8 and has been confirmed as exploited in the wild prior to Google’s patch release.[3][13] Security advisories note that Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux contain fixes for CVE-2026-85046, with the update rolling out to users in early September 2026.[3][13] In the UTA0565 campaign, CVE-2026-85046 appears to be used inside the BlueMoon exploit kit alongside CVE-2026-87491 and CVE-2026-85880, with the final shellcode stage retrieving a file named chrome_cleanup.exe.[6]

Researchers at Volexity report that UTA0565 relies on a network of convincing clone sites, including pages spoofing news outlets, restaurant search portals and corporate training services, to funnel victims into the exploit chain.[5][12] Victims who land on these sites are served malicious HTML such as config.html, which triggers the BlueMoon kit and ultimately downloads the CLEANGULP payload from attacker-controlled infrastructure.[5][6] Analysis of infrastructure linked to the campaign identified the command-and-control domain thecovnresation[.]com, a deliberate typosquat of the legitimate media site The Conversation.[5][14][4]

CLEANGULP is described as a previously undocumented malware family written in C and compiled with Microsoft Visual C, heavily obfuscated via control-flow flattening and indirect calls to frustrate reverse engineering.[5][10][14] On infected Windows hosts, CLEANGULP installs itself as %LOCALAPPDATA%MicrosoftIMEMicrosoftIME.exe and registers a scheduled task named MicrosoftIME to maintain persistence after reboot.[5][10] The malware supports a broad command set, including running arbitrary shell commands, listing processes, uploading and downloading files, and executing beacon object files, giving operators flexible post-compromise control over compromised systems.[5][10][4]

Volexity warns that a patch gap between vendor releases and enterprise deployment windows gives actors like UTA0565 ample time to weaponize fresh bugs before defenses catch up.[5] Defenders are urged to prioritize deployment of the latest Chrome builds, verify that CVE-2026-85046 has been addressed in their environments, and monitor for suspicious scheduled tasks and binaries under the MicrosoftIME path on Windows endpoints.[1][5][13] Network teams should also watch for attempts to reach known CLEANGULP infrastructure, including traffic to domains mimicking The Conversation, and treat such activity as a likely indicator of targeted exploitation.[5][14]

With public proof-of-concept code already circulating for CVE-2026-85046 and multiple vendors tracking active exploitation, the Chrome component of this chain is poised to become a staple in broader threat activity beyond the original UTA0565 campaign.[3][7][11] Until both Chrome and Windows fixes are fully deployed, organizations in media, corporate training and other sectors seen in this campaign should assume that well-resourced adversaries are actively testing similar exploit chains against their users.[5][6][12]

References

  1. NVD-CVE-2026-85046
  2. CVE Record: CVE-2026-85046
  3. Google Chrome Multiple Vulnerabilities
  4. Chinese Hackers Use Fake Websites to Exploit Chrome and Windows Zero-Days
  5. Mind the (Patch) Gap, Part 2: Fake Websites Used to …
  6. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
  7. CVE-2026-85046 – Exploits & Severity – Feedly
  8. Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
  9. CVE-2026-85046 – High Vulnerability (PoC Available)
  10. Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
  11. Google patches actively exploited Chrome zero-day (CVE …
  12. Chinese APT actor uses Chrome and Windows zero-days …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply