A critical remote code execution vulnerability in Tencent’s popular Sogou Input Method for Windows is being actively exploited in the wild, enabling attackers to compromise machines with a single click on a crafted link.[1][4][5] Threat intelligence firms have linked the activity to a China-aligned espionage group that is using the flaw to deploy the GrayRabbit backdoor in targeted networks across East and Southeast Asia.[4][8][13]
Sogou Input Method is one of the most widely used Chinese-language input method editors (IMEs), with hundreds of millions of users across Windows and mobile platforms, making any security defect in the software a high-impact event.[3][11] Previous research from Citizen Lab highlighted encryption weaknesses in Sogou’s Windows and Android keyboards that allowed network eavesdroppers to recover plaintext keystrokes in real time, underscoring the broader privacy and security risks around Chinese IME ecosystems.[3][7][11]
The newly reported flaw, tracked as CVE-2026-51990, affects the Windows version of Sogou Input Method and is rated critical, enabling one-click remote code execution when a victim follows a specially crafted link.[1][5][13] Researchers describe the bug as a chain of three weaknesses: unvalidated command-line argument injection in the custom sgbiz: URI protocol handler, unrestricted URL navigation inside the application’s CEF-based webview, and reliance on an outdated, unsandboxed Chromium 80 engine.[1][13] Together, these issues let attackers pass arbitrary parameters into the IME process and execute malicious payloads in the context of the logged-in user, with no additional prompts beyond the initial click.[1][5][13]
Threat actors identified as UNC3569 are reportedly leveraging CVE-2026-51990 in spear-phishing and watering-hole campaigns, directing targets to malicious pages that trigger the vulnerable protocol handler and drop the GrayRabbit backdoor.[4][5][13] The GrayRabbit malware is used to establish persistent remote access and is associated with espionage-focused operations against government, education, technology, and financial organizations in the region.[4][8][13] While there is currently no evidence of a public proof-of-concept exploit, multiple threat intel feeds classify the vulnerability as “active,” indicating that exploitation is ongoing in targeted attacks rather than broad, commodity campaigns.[5][12][13]
Tencent has released a fix in Sogou Input Method version 16.3.0.3498, which is being pushed to users via the product’s automatic update mechanism, closing the immediate hole by adding stricter checks on URL-bearing switches in the protocol handler.[1][5] However, researchers note that the underlying Chromium configuration and version remain unchanged as of early September, leaving residual risk if new bugs in the embedded browser engine are discovered.[1][13] Some vulnerability trackers also point out that CVE-2026-51990 has not yet been reflected in public NVD listings, and one feed flags earlier attempts to catalog the bug as “identifier could not be verified,” suggesting defenders should rely on vendor guidance and reputable threat-intel sources rather than unofficial CVE references alone.[5][12][13]
For enterprises, the combination of mass deployment, one-click exploitability, and nation-state interest makes hardening around Sogou Input Method a priority. Organizations should ensure all Windows endpoints running Sogou IME are updated to the latest patched version, and consider disabling or tightly controlling custom URI handlers in high-risk environments where possible.[1][5] Given past findings about keystroke interception and encryption flaws across multiple Chinese keyboard apps, security teams should also treat third-party IMEs as critical software components, include them in asset inventories, and monitor for unusual outbound connections or protocol handler invocations that could signal exploitation attempts.[3][7][11]
References
- Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
- Vulnerability in Tencent’s Sogou Chinese Keyboard Can …
- Hackers exploit Tencent app flaw to deploy GrayRabbit malware
- CVE-2026-51990 – Exploits & Severity – Feedly
- Almost a billion users’ keystrokes possibly leaked by Chinese keyboard apps
- Hackers explotan una falla crítica de Tencent para instalar el malware GrayRabbit
- 450 million users exposed to privacy risk due to encryption …
- CVE-2026-85103 – Exploits & Severity
- CVE-2026-0310 – Exploits & Severity – Feedly
