21-09-2026
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
Report completeness: High
Threats:
Uta0565
Typosquatting_technique
Victims:
Asian government entities
Industry:
Government, Ngo
Geo:
Hong kong, China, Asian, Chinese, American
CVEs:
CVE-2026-87491 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- google chrome (<153.0.8010.36)
CVE-2026-85880 [Vulners]
CVSS V3.1: 7.8,
Vulners: Exploitation: True
Soft:
- microsoft windows_10_1607 (<10.0.14393.9512)
- microsoft windows_10_1809 (<10.0.17763.9245)
- microsoft windows_10_21h2 (<10.0.19044.7725)
- microsoft windows_10_22h2 (<10.0.19045.7725)
- microsoft windows_server_2012 (-, r2)
have more...
CVE-2026-85046 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- google chrome (<152.0.7977.82)
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1027, T1036, T1036.005, T1068, T1071.001, T1105, T1140, T1203, T1553.005, T1559.001, have more...
IOCs:
Domain: 9
IP: 1
File: 4
Url: 1
Hash: 1
Soft:
Chrome, Google Chrome, Windows shell, Volexity Volcano
Algorithms:
md5, base64, sha1, sha256, aes, aes-256-gcm
Platforms:
x64
Links:
https://github.com/volexity/threat-intel/tree/main/2026/2026-09-21%20Chrome-part-2