Another China-Linked Hacking Group Caught Exploiting Chrome and Windows Zero-Days
Researchers at Volexity have identified a state-aligned Chinese threat group, tracked as UTA0565, exploiting a chain of three zero-day vulnerabilities in Chrome and Microsoft Windows before patches were available. The attacks occurred between September 3 and 4, and used phishing emails impersonating advocacy organisations such as the Center for American Progress and China Digital Times, as well as messages urging support for a jailed Hong Kong activist, to lure victims to fake websites.
The vulnerabilities involved include two remote-code execution flaws in the JavaScript engine used by Chromium-based browsers (CVE-2026-85046 and CVE-2026-87491), and a privilege escalation flaw in Windows Advanced Local Procedure Call (CVE-2026-85880), which Microsoft disclosed on September 8. Volexity noted that the same exploit components have appeared across multiple Chinese threat groups, suggesting a shared toolkit is being customised and reused by different actors. Security firm Proofpoint has separately linked earlier attacks using the same three-vulnerability chain to several other China-aligned groups, warning that additional attackers could adopt the same techniques.
Because these exploits were used before official patches existed, organisations may have had little warning before being targeted. Both firms say the full scope of these campaigns is likely broader than currently known.