Volexity spots China-aligned UTA0565 exploiting Chrome and Windows zero-days
Volexity reported that China-aligned group UTA0565 exploited a chain of three zero-days on Sept. 3–4: CVE-2026-85046 and CVE-2026-87491 in the Chromium JavaScript engine and CVE-2026-85880 in Windows ALPC. The campaigns used phishing emails and fake sites spoofing the Center for American Progress and China Digital Times.
- UTA0565 exploited three zero-days before disclosure and patching on Sept. 3–4
- CVE-2026-85046 and CVE-2026-87491 are RCE flaws in Chromium; CVE-2026-85880 is a Windows ALPC privilege escalation
- Phishing spoofed the Center for American Progress and China Digital Times
- The group used a previously undocumented malware family tracked as CLEANGULP
Read next
Security