Exploited in the wild Chrome UTA0560 nation-state Windows Google
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
CVE Tools coverage
Chinese state-sponsored groups including UTA0560 and APT31 have been observed exploiting a multi-stage attack chain targeting recent vulnerabilities in Google Chrome and Microsoft Windows. The campaign leverages CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to breach non-governmental organizations and deploy backdoors such as GRIMWEDGE and LONGTALE. This incident highlights significant risks associated with patch gaps where fixes exist in upstream sources but have not yet propagated to stable consumer releases.