Sogou Input Method one-click RCE (CVE-2026-51990); UNC3569 deploys GRAYRABBIT
Gen Digital Threat Labs (Alexandru-Cristian Bardaș, published 10 September 2026) details CVE-2026-51990 in Sogou Input Method for Windows: a one-click remote code execution chain combining unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF webview, and an outdated unsandboxed Chromium/CEF build (libcef.dll reported as CEF 80.1.16 / Chromium 80.0.3987.163). Gen observed UNC3569 exploiting the flaw in the wild via a crafted link to deploy the GRAYRABBIT backdoor. The issue was reported to Tencent on 9 April 2026 and fixed in Sogou Input Method version 16.3.0.3498 (released 21 April 2026): the patch validates URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to approved Sogou/Tencent domains — Gen and BleepingComputer (13 Sep 2026) still note the embedded Chromium remains outdated and unsandboxed. Primary: Gen Digital research; wires: The Hacker News (11 Sep 2026) and BleepingComputer (13 Sep 2026).
- Product
- Sogou Input Method (Windows IME; Tencent)
- Versions
- Vulnerable prior to 16.3.0.3498; patch validates sgbiz: URL args (HTTPS + allowlisted domains)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to Sogou Input Method 16.3.0.3498 or later; treat unexpected sgbiz: links as hostile
Primary: Gen Digital — Gray Rabbits / one-click Sogou backdoor (10 Sep 2026) · Vendor: Gen Digital Threat Labs (researcher) · CVE: CVE-2026-51990 · BleepingComputer — GrayRabbit / Sogou (13 Sep 2026); also THN 11 Sep
