China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs.
Volexity documented campaigns detected on September 1, 2026, in which China-linked actors UTA0560 and JungleBamboo (APT31) chained CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (WebAssembly sandbox escape), and CVE-2026-85880 (Windows kernel privilege escalation in RtlpCreateServerAcl). Victims were lured via links on legitimate U.S. university sites vulnerable to reflected XSS, then served hidden exploit iframes behind a donation-form image. Although a V8 fix had landed in Chromium's source after private August reporting, Chrome had not yet shipped it, creating a patch gap the actors exploited. The two groups installed distinct payloads: UTA0560 delivered the GRIMWEDGE JScript backdoor via DLL side-loading, while JungleBamboo used the SUPERSTOMP loader to install the LONGTALE credential-stealing Chrome extension disguised as Google Gemini.
- UTA0560 and JungleBamboo (APT31) hosted byte-identical exploit shellcode but deployed different espionage payloads.
- Chain abused CVE-2026-85046 (V8), CVE-2026-87491 (WebAssembly escape), and CVE-2026-85880 (Windows kernel privilege escalation).
- Links on legitimate U.S. university sites vulnerable to reflected XSS redirected victims to attacker landing pages.
- Payloads were GRIMWEDGE JScript backdoor for UTA0560 and LONGTALE keystroke-capturing Chrome extension for JungleBamboo.
- Volexity assesses medium confidence a shared exploit developer sold the chain to separate Chinese operators.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… | |
| CVE-2026-85880 | Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain. Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied. | 7.8 | <1% | KEV |
| mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022) | |
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | gitprogram.com | address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in |
| domain | ocr.opusaccel.top | 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2 |
| domain | shinewrist.net | Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in |
| sha256 | 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 | 256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensi |
| sha256 | 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc | mber 2 phishing URL serving the shared Chrome exploit chain 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc SHA-256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 execut |
| url | https://proof.gitprogram[ | gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin |
Full article630 words · extracted from gbhackers.com · click to collapse
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims.
Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome extension.
The intrusion began with spear-phishing emails containing links to legitimate U.S. university websites vulnerable to reflected cross-site scripting.
China-Linked Hackers Chain Chrome Zero-Day
The actors abused those sites as redirectors, sending targets to attacker-controlled landing pages. Victims saw a convincing donation-form image while a concealed iframe launched the malicious exploit chain.
At its center was CVE-2026-85046, a V8 JavaScript engine type-confusion issue. Although a fix had entered Chromium’s open-source code after private reporting in August, Chrome had not yet shipped it.

Volexity characterized this as a “patch gap”: effectively a zero-day for Chrome users despite becoming an N-day in the upstream source tree.
The exploit first achieved arbitrary read/write within the V8 sandbox through CVE-2026-85046, then used CVE-2026-87491, a WebAssembly defect, to escape that sandbox.
A third flaw, CVE-2026-85880 in the Windows kernel component RtlpCreateServerAcl, elevated privileges and broke out of Chrome’s sandboxed renderer. The final shellcode injected into Chrome’s browser process and downloaded a payload chosen through an exeurl parameter.
The exploit was engineered for reliability and stealth. It ran in a Web Worker, preserving the visible browser tab if an exploit attempt crashed, and retried recoverable failures up to five times.
Its reconnaissance stage collected Windows version, token privileges, CPU details, and hypervisor indicators before selectively triggering the kernel exploit against targeted Windows builds.
UTA0560 used financial-themed NGO lures and delivered GRIMWEDGE through a loader chain. A dropper extracted a legitimate executable and sideloaded a DLL, established a five-minute scheduled task called “Windows Scheduled System,” and retrieved an MSI payload.

The MSI executed an in-memory JScript backdoor able to survey hosts, list and manipulate files, enumerate or kill processes, execute commands, and upload files.
JungleBamboo, also tracked as APT31, Violet Typhoon, and TA412, used distinct infrastructure yet hosted byte-for-byte identical exploitation shellcode.
Its SUPERSTOMP loader tampered with Chrome Secure Preferences to install LONGTALE, which masqueraded as a Google Gemini extension. LONGTALE captures keystrokes, form data, cookies, session storage, screenshots, browsing information, and supports remote collection commands.
Volexity assessed with medium confidence that a shared exploit developer provided or sold the chain to separate Chinese operators, likely capitalizing on Chrome’s release delay.
The case underscores how upstream patch disclosures can give well-resourced adversaries a short but operationally valuable exploitation window.
Defenders should update Chrome and Windows immediately, investigate phishing redirects and unexpected browser process behavior, and hunt for suspicious scheduled tasks, extension changes, and outbound connections to listed infrastructure.
Indicators of Compromise
| Indicator | Type | Actor | Description / SHA256 |
|---|---|---|---|
cloud.shinewrist[.]net | Domain | UTA0560 | Exploit-hosting and command-and-control infrastructure |
ocr[.]opusaccel[.]top | Domain | UTA0560 | GRIMWEDGE JScript backdoor C2 endpoint |
206[.]166[.]251[.]164 | IP address | UTA0560 | Host associated with cloud.shinewrist[.]net |
gitprogram[.]com | Domain | JungleBamboo | Phishing, exploit delivery, and C2 infrastructure |
hxxps://proof.gitprogram[.]com/a4/j8 | URL | JungleBamboo | September 2 phishing URL serving the shared Chrome exploit chain |
69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc | SHA-256 | UTA0560 | msgbox.exe GRIMWEDGE loader, a Win32 executable |
5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 | SHA-256 | JungleBamboo | a001 LONGTALE malicious Chrome extension |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/