China-Linked Hackers Exploited One-Click Flaw in Tencent’s Sogou Input Method to Deploy GrayRabbit Backdoor

Security researchers at Gen Digital have disclosed active exploitation of a critical remote-code-execution vulnerability, tracked as CVE-2026-51990, in Tencent’s Sogou Input Method for Windows, one of the most widely installed Chinese-language input method editors with hundreds of millions of installations. The flaw was found while investigating a real-world intrusion attributed to UNC3569, a China-linked threat actor associated with espionage activity.

According to Gen Digital’s Threat Labs, the vulnerability could be triggered with a single click on a specially crafted sgbiz: link, which Sogou Input Method registers as a custom URI handler on Windows systems. Researchers say UNC3569 used the flaw in the wild to deploy a backdoor dubbed GrayRabbit.

Gen Digital reported the vulnerability to Tencent on April 9, 2026, under a 90-day coordinated disclosure timeline. Tencent confirmed the fix was complete and pushed to all users through an automatic update, version 16.3.0.3498, by April 21, 2026. MITRE assigned the CVE identifier on July 10, 2026, and Gen Digital published its technical write-up in September.

Because the patch shipped via Sogou’s automatic-update mechanism months before public disclosure, most current installations should already be running the fixed version. Organizations that permit Chinese-language input method editors on managed Windows endpoints, particularly ones with exposure to targeted espionage activity, are advised to confirm Sogou Input Method is running version 16.3.0.3498 or later.

Sources: Gen Digital (Gen Threat Labs), BleepingComputer.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *