09-09-2026
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
Report completeness: High
Actors/Campaigns:
Uta0560 (motivation: cyber_espionage)
Junglebamboo (motivation: cyber_espionage, information_theft)
Apt31
Threats:
Spear-phishing_technique
Grimwedge
Superstomp_stealer
Longtale_stealer
Credential_stealing_technique
Process_injection_technique
Supply_chain_technique
Victims:
Nonprofit organizations
Industry:
Ngo
Geo:
China, Chinese
CVEs:
CVE-2026-85880 [Vulners]
CVSS V3.1: 7.8,
Vulners: Exploitation: True
Soft:
- microsoft windows_10_1607 (<10.0.14393.9512)
- microsoft windows_10_1809 (<10.0.17763.9245)
- microsoft windows_10_21h2 (<10.0.19044.7725)
- microsoft windows_10_22h2 (<10.0.19045.7725)
- microsoft windows_server_2012 (-, r2)
have more...
CVE-2026-87491 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
CVE-2026-85046 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- google chrome (<152.0.7977.82)
TTPs:
Tactics: 5
Technics: 0
IOCs:
Url: 12
Domain: 8
File: 4
Command: 1
BrowserExtension: 1
Email: 1
IP: 1
Hash: 13
Soft:
Chrome, Google Chrome, Chromium, Windows kernel, Hyper-V, Xen, Windows Kernel Local, Windows Installer, Volexity Volcano
Algorithms:
base64, hmac
Functions:
eval
Win API:
CreateProcessA
Languages:
jscript, javascript, powershell
Links:
https://github.com/asaurusrex/Silent\_Chrome/commit/814fa9c2b75f95b8140ea6d460877772a2d4d507https://github.com/volexity/threat-intel/tree/main/2026/2026-09-09%20Chrome