One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked APT groups reused identical Chrome/Windows zero-day chain against NGOs, deploying GRIMWIDGE backdoor and LONGTALE credential-stealing extension.
Volexity reports that China-linked actors UTA0560 and JungleBamboo (APT31/TA412) ran byte-identical Chrome/Windows exploit chains against NGOs starting September 1, 2026, combining Chrome type confusion CVE-2026-85046, WebAssembly sandbox escape CVE-2026-87491, and Windows kernel flaw CVE-2026-85880. The Chrome bug was fixed in Chromium source but not yet shipped to Chrome users, making it an effective zero-day with an unusual patch gap. UTA0560 delivered the in-memory GRIMWEDGE JScript backdoor, while JungleBamboo deployed the SUPERSTOMP loader installing LONGTALE, a malicious Chrome extension disguised as Google Gemini that steals cookies, session tokens, and keystrokes. Volexity assesses with low confidence the exploit chain was sold or shared among different Chinese end-users.
- Identical shellcode across campaigns suggests shared or sold exploit chain.
- Three-CVE chain achieves V8 sandbox escape and Windows kernel code execution.
- Chrome patch gap: fix in Chromium source but unpatched in Chrome during attacks.
- LONGTALE Chrome extension bypasses profile integrity checks via legacy HMAC fallback.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… | |
| CVE-2026-85880 | Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain. Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied. | 7.8 | <1% | KEV |
| mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022) | |
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |
Full article1,172 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 15, 2026

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each.
Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several NGOs. The emails sent victims to a legitimate US university website, which had a cross-site scripting flaw that attackers used to redirect visitors to their own servers.

The victims were then exposed to a multi-stage attack using a Chrome zero-day CVE-2026-85046. Volexity later found JungleBamboo (also known as APT31, Violet Typhoon, or TA412) using the same exploit chain against different targets. The code was the same, but the infrastructure and final malware were different.
“The exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046), then combines a separate WebAssembly defect to escape the V8 sandbox (CVE-2026-87491). It then exploits a third vulnerability in the Windows kernel (CVE-2026-85880) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.” reads the report published by Volexity. “From there, exploit-chain users can deploy a payload of their choice. Volexity observed two distinct clusters of activity using the exploit chain to deliver different payloads:
- UTA0560 downloaded and deployed the GRIMWEDGE JScript backdoor providing host reconnaissance, file and process management, command execution, and payload delivery capabilities.
- JungleBamboo deployed SUPERSTOMP, a loader that installed the LONGTALE credential-stealing Chrome extension.”
Victims only saw an image of a donation form made to look like it belonged to the targeted organization. In reality, the page was there to steal, not collect, donations.
The core Chrome flaw, CVE-2026-85046, was reported to the Chromium project by a private researcher on August 4, 2026. A fix landed in the open-source Chromium codebase not long after. Google Chrome itself, though, hadn’t shipped that fix yet when the phishing started.
” This created an unusual patch gap: The vulnerability was known and fixed upstream, making it an N-day at the Chromium source level, but there was no patch release for Google Chrome users.” continues the report. “Therefore, the exploit was effectively a zero-day against Google Chrome.”
Someone was watching the Chromium source repository closely enough to catch a fix before most users ever got it, and turned it into a working exploit within weeks. Volexity researchers found byte-for-byte identical shellcode across both campaigns. UTA0560 and JungleBamboo weren’t independently reinventing the same exploit; they were running the same one.
The exploit page was far more sophisticated than it first appeared. It accepted 13 URL parameters to support testing, breakpoints, telemetry, and controlled rollouts.
That level of preparation doesn’t look like a quick attack put together on the fly. It suggests the attackers had built a proper development and testing framework, which was either left in place or deliberately used in the live campaign.
Once code execution lands, the two operators split. UTA0560 used its access to drop a custom loader chain ending in GRIMWEDGE, a JScript backdoor running entirely in memory inside msiexec.exe. It’s compact, under 250 lines, but it covers the basics: file operations, process management, command execution, and file upload.
JungleBamboo took a different route. It deployed a loader Volexity calls SUPERSTOMP, which installs a malicious Chrome extension named LONGTALE. The extension masquerades as a Google Gemini assistant and logs every keystroke, steals cookies and session tokens, and takes screenshots when it spots keywords supplied by its command server.
LONGTALE has no remote code execution command at all. It doesn’t need one. Volexity assesses the credential and session theft alone gave JungleBamboo everything it needed, and extensions like this tend to slip past detection more easily than a standalone executable.
Chrome has spent the last year hardening exactly the kind of tampering SUPERSTOMP relies on. Per-preference encrypted hashes arrived in November 2025, and a full-profile integrity check followed in June 2026. SUPERSTOMP still gets through, by stripping the new hashes, forging the older legacy HMAC values Chrome still accepts as a fallback, and letting Chrome’s own migration logic re-authenticate the tampered profile as legitimate.
“Chrome enables this legacy fallback method by default in its releases as of September 8, 2026; only compiling Chromium from source disables it.” Volexity states. “This technique was added to one of the most popular GitHub repositories relating to silent installation of Chrome extensions on August 6, 2026.”
Worth noting: this exact technique showed up in a popular GitHub repository for silent Chrome extension installs on August 6, 2026, weeks before JungleBamboo’s campaign. The line between public research and operational tradecraft keeps getting shorter.
The attribution work here is tidy. UTA0560’s link to its March 2026 campaigns rests on three points: the same phishing sender address, the same hosting IP for its exploit infrastructure, and a per-host beacon naming scheme that mirrors what UTA0560 used six months earlier.
“Volexity assesses with low confidence that the exploit chain may have been sold, or otherwise provided, to different end-users in China, hence the near-simultaneous campaigns conducted by separate threat actors using distinct post-exploitation malware. Volexity assesses with medium confidence that the short time window offered by the Chrome patch delay necessitated that these threat actors reuse the core exploit code without modification.” states the report. “Furthermore, the payloads used by each threat actor were compiled using different toolsets, suggesting entirely different development environments preferred by each malware developer.”
Proofpoint reported similar findings around the same time. It calls the exploit kit BlueMoon and says JungleBamboo first used it on August 28, several days before Volexity detected the campaign.
Proofpoint identified four different groups using the same code within about two weeks. One, tracked as UNK_LateNight, targeted US aerospace companies with the ShadowPad backdoor. Another, UNK_DoubleCheck, targeted a manufacturing company in Vietnam.
Proofpoint also found an interesting clue about how the exploit may have been developed. Some code artifacts suggest the attackers could have used AI during development. There’s no proof of that, but the diagnostic logs, handover notes, and debugging comments look unusual for a professionally developed exploit.
Google patched CVE-2026-85046 in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83, alongside eleven other fixes. CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, with a September 18 deadline for federal systems to remediate. If your fleet hasn’t relaunched Chrome since early September, it’s worth checking the version number rather than assuming the auto-update did its job.
Volexity’s closing point is the one to actually remember here, and it’s not really about UTA0560 or JungleBamboo specifically.
“As large language models become more popular and effective for rapid vulnerability research and exploit development, Volexity assesses with high confidence that patch-gap vulnerabilities present an even greater risk, as they create an additional time window for threat actors to conduct exploitation campaigns.” concludes the report.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Chrome)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html