Chinese Hackers Exploited Chrome Patch Delay to Launch Attacks Using Three Zero-Days

23.09.2026 6 minutes Author: Newsman

At least four Chinese state-backed hacking groups began exploiting the same zero-day vulnerabilities in Chrome and Windows almost simultaneously. After Google quietly published a fix for a critical Chrome flaw, attackers were able to closely analyze the patch before it reached users.

On August 4, 2026, security researcher Salvatore Gulizia privately reported a serious vulnerability in Chrome’s V8 JavaScript engine to Google. He received a $1,000 bounty for the discovery. By August 7, a fix had already been prepared and published in the public V8 repository.

A few weeks later, at least four Chinese hacking groups began exploiting the flaw in real-world attacks before the fix had reached Chrome users. Researchers found that simply visiting a malicious website was enough to compromise a device. The attackers chained Chrome and Windows vulnerabilities together to escape the browser sandbox and gain full control of the system.

After remaining publicly available for nearly a month, the fix finally reached the stable version of Chrome on September 3. The update was rolled out gradually over several days, meaning some users remained vulnerable for even longer. Researchers had already pointed to this unusual gap between the appearance of a fix in the source code and its actual deployment to users.

“This vulnerability was already known and its fix had been published, effectively making it an N-day at the Chromium source-code level. However, the patch was still unavailable to Google Chrome users. In practice, this meant the exploit remained a 0-day for Google Chrome,” Volexity previously said.

Just a few days later, on September 8, Chrome moved to a two-week release cycle instead of the previous four-week schedule. Google had first announced the change back in March 2026. The new cycle shortens the gap, but does not eliminate the problem entirely. This is known as the N-day window, when patched code is already publicly available and can be analyzed by attackers, including with the help of AI, while the actual update has not yet been installed on end-user devices.

“With AI-powered automated detection tools and a growing number of community bug reports, the volume of fixes is increasing. Shorter release cycles make security updates significantly easier to manage. Reducing the time between a fix appearing in the open-source codebase and being delivered to end users allows us to minimize the N-day window as much as possible,” Google said in a blog post.

Widespread Exploit Use

The first attacks were observed on August 28 by Proofpoint and Volexity. China-linked threat actors chained together three vulnerabilities: the previously mentioned V8 flaw, another V8 vulnerability used to escape the browser sandbox, and a Windows zero-day for privilege escalation, which allowed successful attackers to gain SYSTEM-level privileges. Researchers dubbed the three-exploit chain BlueMoon.

A few days later, another targeted phishing campaign with an espionage objective was uncovered. The number of hacking groups using the same exploit chain later grew to four. In a new Volexity report, researchers described additional threat actors deploying the exploit kit through fake websites. The attackers cloned pages belonging to nonprofit organizations and tried to convince victims that they were visiting legitimate resources.

“Volexity identified additional campaigns using the same exploit chains on September 3 and 4, 2026, while the vulnerabilities were still unpatched,” the report said.

“Such widespread use across multiple threat actors appears to indicate coordinated activity within the Chinese computer network operations community.”

Researchers believe the exploit kit may have been shared among different groups, which then adapted it for their own campaigns. The true scale of its use is likely significantly larger than what researchers were able to observe. The attackers had roughly four weeks to work with the vulnerabilities, and AI tools were likely used extensively during exploit development. One indication is the unusually detailed logging and code comments found in the malware, something that is uncommon in espionage tools.

Fake Websites Imitated Legitimate Resources

In the latest attacks, hackers created convincing copies of legitimate websites, often using domains with minor spelling changes. One phishing campaign targeted government agencies in Asia. Victims were encouraged to publicly support imprisoned Hong Kong activist Chow Hang-tung, while the messages included links to fake websites impersonating China Digital Times and the Center for American Progress.

Simply opening one of these websites was enough to trigger the infection. The page launched a three-exploit chain, then downloaded malicious components, disabled Mark of the Web, a Windows security mechanism that flags potentially dangerous files downloaded from the internet, and finally executed the malware through the command shell in a way designed to remain unnoticed by the user.

The phishing lure used in the attack.

The malware itself had also not been previously documented. It created a scheduled task to maintain persistence on the system and allowed its operators to upload and download files, view running processes, access a command shell, and execute additional malicious components. Once activated, the malware could run commands, enumerate processes, transfer files in both directions, and launch additional code received from its operators.

“Using real content from legitimate websites as bait continues to be an effective way to reduce user suspicion,” the researchers warned.

At Least Four Other Threat Actors Were Previously Identified

The first BlueMoon campaigns identified by Proofpoint targeted a small number of nongovernmental organizations, mining companies, and physical commodities trading firms in the United States. The attackers posed as students from several universities who were supposedly looking for internship opportunities. The malicious websites prompted victims to install browser extensions disguised as Google Gemini.

If a victim followed a link to an attacker-controlled domain hosting the exploits, a download page appeared within seconds. At the same time, the browser launched an exploitation attempt, after which the user was redirected to a legitimate website, according to a Proofpoint report.

Another group targeted U.S. aerospace companies using fake requests for quotations and other B2B-themed lures. If the attack succeeded, a backdoor was installed on the compromised system. Another likely espionage-focused actor targeted a manufacturing company in Vietnam using messages sent from a compromised email account belonging to a Southeast Asian government. A fourth group targeted users in Singapore and Indonesia, where it deployed previously undocumented malware.

All three vulnerabilities used to deploy the malware have now been patched by Google and Microsoft:

  • The type confusion vulnerability in Chromium’s V8 JavaScript engine is tracked as CVE-2026-85046.

  • The V8 sandbox escape vulnerability is tracked as CVE-2026-87491. It allowed remote attackers to execute arbitrary code within the sandbox.

  • The Windows kernel zero-day vulnerability that enabled local privilege escalation is tracked as CVE-2026-85880.

Users are advised to install the latest Chrome, Windows, and other software updates as soon as possible and to avoid clicking suspicious links.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.