ClickFix cache smuggling bypasses the Windows Run character limit
ClickFix payload staged in the browser cache

ClickFix cache smuggling bypasses the Windows Run character limit

Microsoft Threat Intelligence has described a ClickFix variant that does not download its first payload at the moment the victim presses Enter. The script is already sitting in the browser cache, disguised as an image.

What happened

Compromised sites prefetch the payload into the cache. The lure then asks the user to paste a short command into the Windows Run dialog. Run truncates input at about 260 characters, so older ClickFix chains had to stay short. This one points at a file that is already on the PC.

In the chain Microsoft described, a script searches the Firefox profile cache for a file of an expected size, copies that entry, and runs it. Later stages steal browser and device credentials. A CAPTCHA or a fake browser error is the usual prompt. The user runs the command.

Who is affected

Any Windows user who can be talked into pasting a "fix" into Run, Terminal, or PowerShell. Help desks, shared PCs, and staff who troubleshoot their own browsers are the practical target.

  • Users who visit compromised sites that stage a fake image in the browser cache
  • Environments that still allow the Run dialog and unsigned script hosts
  • Teams that only alert on a fresh download, and miss a copy from the browser cache

What to do now

Tell staff that a CAPTCHA or error page must never ask them to paste a command into Run, Terminal, or PowerShell. Hunt for script hosts launched from the Run history, and for cache files copied into the user Temp folder and executed.

Source: The Hacker News, citing Microsoft Threat Intelligence.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Exchange CVE-2026-96940: signed-in users can read other mailboxes
on-prem Exchange mailbox access across users