CVE
CVE-2026-85880
- First Reported
- Sep 9, 2026
- Latest Reported
- Sep 21, 2026
Reported Context (4)
- chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors. UTA0565 Used Fake Websites to Deliver Chrome and Windows Zero-Day Exploits
- CVE-2026-85880 -- Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Microsoft’s September Patch Tuesday Addresses 973 CVEs Across 39 Product Families
- It then exploits a third vulnerability in the Windows kernel (CVE-2026-85880) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process. Volexity Details Chinese Actors’ Chrome–Windows Exploit Chain Used in Two Espionage Campaigns
- a Windows kernel Local Privilege Escalation (LPE) zero-day present in older Windows builds (assigned CVE-2026-85880), which is used to escape the renderer process. Multiple State-Aligned Threat Actors Rapidly Adopt BlueMoon Chrome and Windows Exploit Chain
CVE (43)
Malware (6)
People (2)
Threat Actors (7)
MITRE ATT&CK (30)
Vendors (6)
Products (45)
Tools (2)
Industries (10)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.