Code Defence Cyber security

Chinese threat actor UTA0565 exploits Chrome and Windows zero day chain to deploy CLEANGULP malware

Threat intelligence disclosures have detailed a sophisticated cyber espionage campaign leveraging a full browser sandbox escape and privilege escalation zero day chain. Chinese espionage actors masqueraded as non-governmental organizations to deliver stealthy backdoors to target enterprise endpoints.

The exploit chain combines Google Chrome V8 engine type confusion flaws CVE-2026-85046 and CVE-2026-87491 with Windows Advanced Local Procedure Call ALPC heap buffer overflow CVE-2026-85880. Unauthenticated users visiting compromised websites trigger the browser exploit to escape renderer sandboxes, subsequently exploiting the Windows ALPC flaw to elevate execution privileges to SYSTEM level. Threat actors use the elevated access to drop CLEANGULP, a modular backdoor capable of exfiltrating browser session cookies, harvesting local system credentials, and establishing persistent reverse proxy tunnels.

Chaining browser zero-days with local operating system kernel flaws completely defeats client workstation defenses. When threat actors achieve SYSTEM privilege via web drive-by attacks, adversaries bypass endpoint detection and response drivers, leaving enterprise networks exposed to unmonitored lateral movement.

– Ensure Google Chrome and Chromium-based browsers are updated to release 152.0.7977.82 or higher across all corporate workstations.

– Force immediate installation of Microsoft September 2026 Patch Tuesday security updates addressing Windows ALPC vulnerability CVE-2026-85880.

– Deploy browser isolation solutions and strict web filtering policies to isolate untrusted external web navigation.

– Monitor endpoint process telemetry for anomalous child processes spawned by browser renderer processes.

Endpoint security resilience relies on rapid multi-tier patch deployment and strict browser process isolation to ensure enterprise workstations remain protected against sophisticated zero-day drive-by exploit chains. #CodeDefence #Google #Chrome #Microsoft #Windows #ZeroDay #V8 #ALPC #CLEANGULP #EndpointSecurity
/

Scroll to Top