ADVERTISEMENT

Chinese hackers weaponize “the gap” by reverse engineering Chrome fixes before they reach users

Open source stumble: fixes are released publicy before they reach users, and attackers have weeks to weaponize them.

chrome vulnerability

Chrome vulnerability. Image by Cybernews, Shutterstock (vectorfusionart, ValeriyPH, Parinussa Revy)

Ernestas Naprys
Ernestas Naprys Senior Journalist
September 22, 2026 4 min read
Key takeaways:

Widespread adoption

China hacker
Image by Shutterstock.
ADVERTISEMENT

Fake sites mimic legitimate organizations

phishing lure
A phishing lure used in an attack. Image by Volexity.

At least 4 more attackers were detected previously

If the target clicked on the provided link to the actor-controlled domain hosting the exploits, they were shown a loading page for several seconds while the browser exploit was attempted, before being redirected to a legitimate website,
the Proofpoint report reads.

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
  • A type-confusion vulnerability in Chromium’s V8 JavaScript engine is tracked as CVE-2026-85046.
  • A V8 sandbox escape is tracked as CVE-2026-87491. It allowed remote attackers to execute arbitrary code inside the sandbox.
  • A Windows kernel Local Privilege Escalation (LPE) zero-day vulnerability was assigned the CVE-2026-85880 identifier.
Ernestas Naprys
Senior Journalist
ADVERTISEMENT