Chinese Group’s Chrome–Windows 0‑Day Chain and F5 BIG‑IP Flaw Show Browser and Gateway Exposure
Researchers say Chinese threat actor UTA0565 used three previously unknown Chrome and Windows vulnerabilities in a single chain to escape the browser sandbox and deploy CLEANGULP malware, while F5 warns that a BIG-IP APM zero-day (CVE-2026-94127) is being exploited for unauthenticated remote code execution.
Two separate zero-day campaigns show how attackers are going after both individual browsers and the gateways that sit in front of corporate networks.
Security researchers report that a Chinese threat actor tracked as UTA0565 exploited three Chrome–Windows zero-days in a single chain. The group used fake websites as lures, then combined the unknown flaws to break out of Chrome’s sandbox and achieve remote code execution on Windows systems. The end of the chain deployed malware known as CLEANGULP.
Using three previously unknown vulnerabilities together indicates a high level of investment in the operation. Chrome’s sandbox is designed to contain damage inside the browser; escaping it and running code on the underlying operating system is significantly harder.
At the same time, F5 has confirmed active exploitation of a critical zero-day in its BIG-IP Access Policy Manager (APM) product. The vulnerability, tracked as CVE-2026-94127, allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. F5 has released hotfixes, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog.
Taken together, the cases underline where attackers see leverage: in widely used browsers that sit on every desktop, and in access-management systems that decide who can reach sensitive applications.
Signals to watch now are how quickly organizations roll out Chrome and Windows patches once available, how many BIG-IP APM customers apply F5’s hotfixes, and whether incident reports show CLEANGULP or CVE-2026-94127 being used beyond the initially identified campaigns.
Sources
- OSINT