Chrome Windows zero-day chain

"Chinese hackers were chaining Chrome and Windows zero-days for weeks"

(yesterday) · 3 min read · By Future Technology

Key takeaways

  • Two Chrome V8 zero-days, CVE-2026-85046 and CVE-2026-87491, were chained with a Windows flaw
  • At least two separate Chinese state-linked groups ran the campaign independently
  • Fake websites delivered the exploit chain, no download required beyond visiting a page
  • One campaign was active while the Chrome bug was still unpatched

A bug chain, not a bug

A type confusion bug in Chrome's JavaScript engine doesn't sound like much on its own. Chained with the right second exploit, it's a full device compromise delivered by nothing more than a fake webpage.

That's what Volexity documented in a report published 21 September, describing a campaign it calls Mind the Patch Gap, Part 2. Researchers found at least two separate Chinese state-linked threat actors running attacks that combined two Chrome zero-days in the V8 engine, tracked as CVE-2026-85046 and CVE-2026-87491, with an exploit targeting Windows. The combination let attackers break out of Chrome's sandbox entirely and run code directly on the victim's machine.

How the attack worked

Both campaigns used fake websites as the delivery mechanism. A visitor didn't need to download anything or click through a security warning. Simply loading a crafted page was enough to trigger the Chrome bug, which on its own would normally be contained inside the browser's sandbox. The Windows exploit is what broke that containment, handing the attacker code execution outside the browser.

Google patched CVE-2026-85046 on 3 September and CVE-2026-87491 shortly after, in Chrome 153. But Volexity's research shows a third, separate Chinese threat actor was running attacks using the same chain in early September, while the Chrome bug was still unpatched. That's the patch gap in the report's title: the window between a vulnerability being actively exploited and a fix actually reaching users.

Why three groups, one exploit chain

It's unusual to see multiple unrelated threat actors using the same zero-day chain simultaneously. It suggests either a shared exploit broker supplying several Chinese operations at once, or that knowledge of the flaw spread through intelligence-sharing channels faster than Google could ship a fix. Either way, it points to a maturing exploit supply chain where high-value browser bugs get reused across operations rather than staying exclusive to whoever found them first.

CVE-2026-85046 was Chrome's sixth zero-day patched in 2026. CVE-2026-87491 was the seventh. Chrome has now had a zero-day roughly every six weeks this year.

What to do

If your Chrome browser hasn't restarted in a while, it might still be running the vulnerable version even after the update downloaded, since Chrome only applies updates on relaunch. Close and reopen the browser, or check chrome settings help to force an update check. The same applies to Windows: make sure September's cumulative updates have actually installed, not just downloaded.

This is also a reminder that browser security depends on more than just the browser. A fully patched Chrome sitting on an unpatched Windows install is still exploitable through exactly this kind of chain. Patch both, and do it this week rather than at the next scheduled cycle.

Sources

    More from Future Technology