< Back to all clusters
[TECHNOLOGY] · China · 3 sources

started · updated

Tencent Sogou Input Method vulnerability exploited to deploy GrayRabbit malware

Cybersecurity researchers at Gen Digital have identified a critical one-click remote code execution (RCE) vulnerability in Tencent’s Sogou Input Method for Windows. The flaw, identified as CVE-2026-51990, is being actively exploited in the wild by the China-aligned threat group UNC3569 to deploy the GrayRabbit backdoor malware.

The attack chain utilizes three distinct weaknesses within the Sogou application: an unvalidated command-line argument injection in the sgbiz: URI, unrestricted URL navigation in a CEF-based webview, and an outdated, unsandboxed Chromium 80 browser engine. The exploit begins when a victim clicks a crafted custom URI, which triggers a protocol handler to pass attacker-controlled arguments to a legitimate executable. This subsequently directs the embedded webview to load a malicious URL, allowing the attacker to achieve code execution and install the malware.

Sogou Input Method is a widely used Windows application for typing Chinese characters and is reported to have hundreds of millions of installations in China.

Entities

Gen Digital · GrayRabbit · Sogou Input Method · Tencent · UNC3569