TWO China-linked threat groups used the same Chrome and Windows exploit chain against non-governmental organisations (NGOs), according to Volexity. The activity began on 1 September 2026, when UTA0560 sent spear-phishing emails directing targets through a legitimate US university website. Attackers exploited cross-site scripting on that site to redirect visitors to their own infrastructure.
Victims were shown a convincing donation form, while the attackers used the page to deliver a multi-stage exploit involving Chrome CVE-2026-85046, a V8 sandbox escape (CVE-2026-87491) and a Windows kernel flaw (CVE-2026-85880).
The exploit gained arbitrary read/write access in the V8 sandbox, escaped Chrome’s sandbox and injected code into the browser process. Volexity found byte-for-byte identical shellcode in UTA0560 activity and campaigns attributed to JungleBamboo, also known as APT31, Violet Typhoon or TA412. The groups used different infrastructure and payloads: UTA0560 deployed the in-memory GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE Chrome extension.
Masquerading as a Google Gemini assistant, LONGTALE logged keystrokes, stole cookies and session tokens, and captured screenshots based on command-server keywords.
CVE-2026-85046 had already been fixed in Chromium’s source code after being reported on 4 August, but Google Chrome had not yet shipped the fix when exploitation began, creating what Volexity called a patch gap. Google addressed it on 3 September in Chrome 152.0.7977.82 or .83, and CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 4 September, with an 18 September remediation deadline for federal systems. Volexity assesses with low confidence that the exploit chain may have been supplied to multiple Chinese operators.