Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials
Brief
A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage malware, and steal browser credentials.
According to Volexity, UTA0560 and JungleBamboo, also tracked as APT31, Violet Typhoon, and TA412, used an identical multi-stage exploit chain in spear-phishing operations against different victim sets.
The campaign abused Chrome vulnerability CVE-2026-85046 , a type-confusion flaw in the V8 JavaScript engine.
Chinese Hackers Chain Chrome and Windows Zero-Days
Although a fix had entered the open-source Chromium codebase, it was not yet available in a released Chrome update during the attacks. This created a patch-gap condition: technically an N-day in Chromium source, but an effective zero-day for Chrome users.
