Threats & Adversaries · Credential Theft

ClickFix Uses Browser Cache to Evade Run Limits

Microsoft says ClickFix campaigns are using browser cache smuggling to turn a pasted Windows Run command into execution of a VBScript payload that targets credentials. The trick is that the malicious script is preloaded into the browser cache first, disguised as an image file, so the victim is not fetching it at launch.

That matters because the normal Run-dialog character limit and download-based defenses never see a long remote command or a fresh web pull. Microsoft’s observed chain then copies the cached file into a .vbs file, runs it with wscript.exe, and moves on to in-memory stages that can reach browser and device credentials.

For Windows environments where users are trained to paste instructions into Run, the browser cache has become part of the execution path, not just a browsing artifact. If defenders only watch for obvious downloads or oversized paste-run payloads, this class of ClickFix traffic can still land on the endpoint and continue past the first prompt.

1 source · 6h ago

CVE-2026-6854

NVD KEV

CVSS 7.5 HIGH: the My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via… EPSS 2% (75th percentile).

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: ClickFix Uses Browser Cache to Evade Run Limits

More from today