Chrome Bug Fixed in Chromium Was Used Against NGOs Before Chrome Shipped It
Security / news
Chrome Bug Fixed in Chromium Was Used Against NGOs Before Chrome Shipped It
Volexity says two Chinese groups chained CVE-2026-85046, CVE-2026-87491 and a Windows kernel bug from September 1, before Chrome 153 carried the fix.

Two Chinese threat actors were sending a Chrome and Windows exploit chain to victims from September 1, while the browser bug that started it was already fixed in Chromium source but had not reached a Chrome release. An attacker needs a victim to open a phishing link in an unpatched Chrome on Windows.
The mitigation is two updates. Move Chrome to 153.0.8010.36 or later (153.0.8010.37 on Windows and macOS also counts), and install the Windows update for CVE-2026-85880, which CISA added to its Known Exploited Vulnerabilities catalog on September 8.
The three bugs in the chain
Volexity's September 9 report ties three CVEs together, each doing one job.
| CVE | Component | Role in the chain |
|---|---|---|
| CVE-2026-85046 | Chrome V8 | Type confusion, arbitrary read and write inside the sandbox |
| CVE-2026-87491 | Chrome V8 / WebAssembly | Out-of-bounds write used to escape the V8 sandbox |
| CVE-2026-85880 | Windows kernel | Local privilege escalation |
CVE-2026-85046 was reported to the Chromium project on August 4 by Salvatore Gulizia (Serotav), who received a $1,000 bounty, according to Help Net Security. Help Net Security gives it a CVSS score of 8.8 and reports that Google acknowledged that "an exploit for CVE-2026-85046 exists in the wild." Chrome 152.0.7977.82 carries the fix.

Why it counts as a zero-day
Volexity's assessment is that the bugs were "known and fixed upstream, making it an N-day at the Chromium source level, but there was no patch release for Google Chrome users. Therefore, the exploit was effectively a zero-day against Google Chrome."
The gap is a product of Chrome's release cadence. The Hacker News describes two N-day bugs "addressed in Chromium, but not in Chrome." Anyone reading the public Chromium commits could see the fixes. Volexity raises the possibility that one exploit developer sold the chain to both groups after working from those changes, which would explain two actors using the same code at once.
| Date (2026) | Event |
|---|---|
| August 4 | CVE-2026-85046 reported to Chromium |
| August 6 | CVE-2026-87491 found by Jihyeon Jeong, Compsec Lab, Seoul National University ($2,500 bounty) |
| September 1 | Volexity sees the first phishing waves |
| September 2 | Second JungleBamboo wave with an updated payload |
| September 8 | Chrome 153.0.8010.36 ships the CVE-2026-87491 fix; CISA lists CVE-2026-85880 |
| September 9 | CISA lists CVE-2026-87491; Volexity publishes |
Who was targeted
UTA0560 sent donation-themed phishing to US-based NGOs and installed GRIMWEDGE, a JScript backdoor that Volexity says runs to fewer than 250 lines with no built-in lateral movement. Volexity rates its attribution of that actor as high, based on a shared sender address, a hosting IP and beacon habits that match March 2026 activity.
JungleBamboo, which Volexity links to APT31, Violet Typhoon and TA412, used broader lures. Its payload included LONGTALE, a Chrome extension disguised as Google Gemini that logs keystrokes, copies form fields, steals cookies and sends captured data out at 30-second intervals.
Both actors abused a reflected cross-site scripting flaw on a legitimate university website, so the phishing link pointed at a real domain before a hidden iframe loaded the exploit.
What is exploited and what is not
The Hacker News counts CVE-2026-87491 as the seventh Chrome zero-day patched in 2026. CISA's own listing for it gives no due date, while The Hacker News reports a September 23 deadline for federal civilian agencies. The two accounts differ, and CISA's page is the one to trust for the deadline.
The 8.8 score on CVE-2026-85046 understates the risk once the bugs are chained: the V8 flaws stay inside the browser, and the Windows kernel bug supplied the step to the operating system. Two earlier exploited-bug stories here show the same pattern of a patch trailing the attack: F5's BIG-IP APM zero-day was exploited before its hotfix, and Microsoft's record Patch Tuesday carried two exploited local bugs.
Defenders can look for a scheduled task named "Windows Scheduled System" and for changes to Chrome's Secure Preferences file, both of which Volexity lists. Patch first, then hunt.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.