One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Volexity uncovered two China-linked groups, UTA0560 and JungleBamboo, which since September 1, 2026, used a single zero-day chain in Chrome (CVE-2026-85046) and Windows against NGOs. The patch was in Chromium source but not released to Chrome users, making the exploit zero-day.
- Chain uses CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880
- UTA0560 deployed GRIMWEDGE backdoor, JungleBamboo used LONGTALE extension
- LONGTALE masquerades as Gemini assistant and steals passwords and cookies
- Fix was in Chromium but not in Chrome at the time of the attack
Read next
Security