Chrome and Windows Zero-Day Chain: What Pittsburgh SMBs Should Do Now

What happened
Reporting syndicated through feeds.feedburner.com — Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware — describes a Chinese threat actor tracked as UTA0565 using a recently disclosed Chrome-plus-Windows exploit chain while the flaws were still zero-days. The activity was observed on September 3 and 4 of this year, and the delivery mechanism was fake websites rather than email attachments or malicious documents.
Three CVEs are named: two in Google Chrome (CVE-2026-85046 and CVE-2026-87491) and one in the Windows Advanced Local Procedure Call subsystem (CVE-2026-85880). Chained together, they were used to break out of the browser and land malware the researchers call CLEANGULP. We are not going to speculate on the full post-exploitation behavior, persistence method, or which industries were targeted — those details are not in the summary we have, and they are worth verifying directly against Google's and Microsoft's advisories plus your security vendor's own threat intel feed before you brief your leadership team.

Why this matters for Pittsburgh SMBs
Most of the scary headlines we forward to clients involve something you can opt out of: an unpatched VPN appliance you do not own, a niche file-transfer product, a plugin nobody here uses. This one is different. Chrome on Windows is the default working environment for essentially every professional services firm, CPA practice, and law office in the region. There is no "we do not run that" exemption.
The delivery method matters even more than the CVEs. Fake websites mean no phishing attachment for your mail filter to strip and no user decision that clearly looks wrong. An attorney researching opposing counsel, a controller pulling down a vendor form, an estimator checking a supplier spec sheet — normal browsing, normal-looking site, and on an unpatched machine the browser sandbox stops being a boundary. That is why we treat browser patch latency as a security control and not a convenience item.
For our regulated clients the downstream consequences scale fast. If you are a medical or dental practice, unauthorized access to a workstation that touches ePHI starts a HIPAA risk analysis and a breach-determination clock you do not want to be guessing your way through. If you are a defense supplier working toward or maintaining CMMC Level 2, workstations handling CUI fall squarely inside your assessment boundary, and "we patch when users reboot" is not a defensible answer to a flaw-remediation control. Financial advisors and accounting firms under the FTC Safeguards Rule have documented obligations around vulnerability management and monitoring. SOC 2 shops will get asked for evidence, not assurances.
Practical note on timing: the exploitation window described in the reporting was the first week of September, and as of today, September 23, 2026, that is roughly three weeks behind us. Any endpoint that has not restarted Chrome or taken a Windows cumulative update in that span has been carrying exposure through most of the month.
What to do about it this week
- Confirm real-world Chrome versions, not policy intent. Chrome patches download quietly but only apply on relaunch, and staff who never close their browser can sit on a stale build for weeks. Pull an actual inventory of installed versions across every managed endpoint and compare it to the fixed build Google lists for CVE-2026-85046 and CVE-2026-87491.
- Verify the Windows side separately. The ALPC vulnerability (CVE-2026-85880) is what turns a browser compromise into a system compromise. Check that your latest Windows cumulative update is installed and rebooted on every device, including the machines that live on desks nobody reboots — reception, conference rooms, shop-floor terminals, shared scheduling stations.
- Force a browser relaunch fleet-wide. Push a managed policy or a scripted relaunch prompt instead of hoping users comply. If you have Edge or other Chromium-based browsers in the mix, they inherit the same engine and need the same treatment.
- Do not forget the unmanaged edges. Personal laptops on BYOD, that one legacy workstation vendor support insists must not be touched, contractor devices, and Remote Desktop hosts. These are where our patch management reviews most often find the gap.
- Hunt, do not just patch. Ask whoever runs your EDR tooling to review the September 3 to 4 window forward for suspicious child processes spawned by Chrome, unexpected outbound connections, and new persistence entries. Patching closes the door; it does not tell you whether someone already walked through.
- Tighten browser-side surface area. Audit installed extensions and remove what nobody can justify, disable unnecessary plugins, and make sure DNS or web filtering is actually inspecting traffic rather than sitting in monitor-only mode. Fake-site delivery is exactly the scenario filtering is supposed to blunt.
- Write down what you did. One dated page: scope checked, versions confirmed, exceptions and their compensating controls, hunt results. Your next SOC 2 or CMMC assessor will ask how you responded to a known exploited vulnerability, and a short contemporaneous record beats a reconstructed story every time.
A note for anyone rolling out AI tooling: browser-based assistants and Microsoft 365 Copilot pilots expand how much sensitive data flows through the browser session. That is worth folding into your AI readiness assessment and acceptable-use policy rather than handling as a separate track.
How we help
For our managed IT clients, browser and OS patch verification is already part of the monthly cycle, and our security team is reviewing telemetry against this activity now. If you are not sure who is watching your Chrome versions, whether your EDR would flag a sandbox escape, or how flaw remediation is documented for your next audit, our vCIO team can walk your environment and give you a straight answer.
Call 724.888.7007 or reach us through the contact form and we will schedule a patch-posture and exposure review this week.
Related reading

Fake LastPass Installer Kills EDR With a Signed Driver
A fake LastPass Authenticator installer uses a Microsoft-signed driver to disable antivirus and EDR. What Pittsburgh SMBs should verify and fix this week.

ClickFix Fake Updates Are Now Delivering ChainScript RAT
ClickFix fake-update lures are deploying a new RAT called ChainScript, posing as Teams, Zoom and Spotify. What Pittsburgh SMBs should do this week.

Fake GitHub Repos Are Pushing Infostealers at Your Staff
Fake LastPass Authenticator GitHub repos are spreading the Rapuncel infostealer. What Pittsburgh SMBs should verify and lock down this week.