securityaffairs.com 15 Sept 2026, 10:17 UTC

China-Linked Groups Exploited Chrome Patch Gap to Target NGOs

China-Linked Groups Exploited Chrome Patch Gap to Target NGOs
CyberSIXT Evidence Panel

TWO China-linked threat groups used the same Chrome and Windows exploit chain against non-governmental organisations (NGOs), according to Volexity. The activity began on 1 September 2026, when UTA0560 sent spear-phishing emails directing targets through a legitimate US university website. Attackers exploited cross-site scripting on that site to redirect visitors to their own infrastructure.

Victims were shown a convincing donation form, while the attackers used the page to deliver a multi-stage exploit involving Chrome CVE-2026-85046, a V8 sandbox escape (CVE-2026-87491) and a Windows kernel flaw (CVE-2026-85880).

The exploit gained arbitrary read/write access in the V8 sandbox, escaped Chrome’s sandbox and injected code into the browser process. Volexity found byte-for-byte identical shellcode in UTA0560 activity and campaigns attributed to JungleBamboo, also known as APT31, Violet Typhoon or TA412. The groups used different infrastructure and payloads: UTA0560 deployed the in-memory GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE Chrome extension.

Masquerading as a Google Gemini assistant, LONGTALE logged keystrokes, stole cookies and session tokens, and captured screenshots based on command-server keywords.

CVE-2026-85046 had already been fixed in Chromium’s source code after being reported on 4 August, but Google Chrome had not yet shipped the fix when exploitation began, creating what Volexity called a patch gap. Google addressed it on 3 September in Chrome 152.0.7977.82 or .83, and CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 4 September, with an 18 September remediation deadline for federal systems. Volexity assesses with low confidence that the exploit chain may have been supplied to multiple Chinese operators.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline