Security & AI news

Browser exploit chains · By FireAI Security & Research Team · Published

Volexity links a Chrome and Windows exploit chain to fake news sites aimed at Asian government staff

Volexity says the group UTA0565 chained two Chrome flaws and one Windows flaw through cloned websites on 3 and 4 September. What the reports say and what to update.

Stacked levels and the FireAI knight mascot, next to the words “Chrome and Windows flaws chained via fake sites.”

Volexity researchers Damien Cash and Tom Lancaster say a threat group they track as UTA0565 chained two Chrome vulnerabilities and one Windows vulnerability to leave the browser sandbox and run code on victims' computers, The Hacker News reported on 23 September. The attacks were seen on 3 and 4 September and used cloned websites of media outlets and non-governmental organisations.

Background

Chrome runs web pages in a sandbox that limits what a page can do. An attacker who wants control of the computer needs two steps: a flaw to run code inside the browser, and a second flaw in the operating system to get out of the sandbox. Such a chain is valuable because a visit to a page can be enough [1].

What the report describes

The chain combines CVE-2026-85046 and CVE-2026-87491 in Chrome with CVE-2026-85880 in the Windows Advanced Local Procedure Call component. Phishing emails, some in Chinese and some in English, went to Asian government entities and pointed to cloned sites that imitated China Digital Times and a second organisation. One email referred to the imprisoned Hong Kong activist Chow Hang-tung [1].

A hidden frame on each cloned page loaded a script from the BlueMoon exploit kit, and the final stage downloaded a file named chrome_cleanup.exe. Volexity calls the payload CLEANGULP. According to the report, it runs shell commands, lists processes, uploads and downloads files and executes further modules, and it talks to a server on a domain that imitates a news site [1].

Implications for Mac users

The final step used a Windows component, so this chain as described targets Windows computers running Chrome. The report does not say whether the Chrome flaws also affect Chrome on macOS, or whether an equivalent macOS step exists. The named targets are government staff, and the report does not describe attacks on the general public [1].

Recommendations

  1. Update Chrome and any other Chromium browser to the current release. On a Mac, open the browser menu, choose About, and let it check.
  2. Apply Windows updates on any Windows machine in the household or office.
  3. Treat an emailed link to a news article you did not seek as unverified, and check the sender and address.
  4. Compare the address of a familiar site with the one in your browser before signing in.

Relevance to FireAI

FireAI runs on macOS and does not protect Windows machines, so it does not address this chain as described. It does not fix browser flaws or verify websites. On a Mac, its role in a comparable case is the follow-up: a downloaded executable that has no rule triggers a prompt before it connects, and the Threats page and world map show where connections go.

Limitations

The full scope of compromise is not known, and the report says several Chinese groups probably share the toolkit. It does not state whether the flaws were patched before or after the attacks, and it gives no count of victims [1].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. The Hacker News, 23 September 2026: Chinese hackers exploit a Chrome and Windows flaw chain (reporting Volexity research)