Gen Threat Labs (published Sep 10; amplified Sep 13–14 by BleepingComputer and SecurityWeek) reports CVE-2026-51990 in Tencent’s Sogou Input Method for Windows. A crafted sgbiz: link hands Windows to biz_helper.exe, which launches legitimate SGMyInput.exe with attacker-controlled arguments. The skincenter path opens a CEF webview and navigates to an attacker URL with no scheme or domain check. That webview runs Chromium 80 (≈ March 2020) with the sandbox disabled and same-origin protections stripped — so a single click can become user-privilege code execution.
Gen observed the chain in an active UNC3569 (PRC-nexus) intrusion delivering GRAYRABBIT, the modular backdoor Google Threat Intelligence has tied to that cluster. The exploit page used a Chromium V8 bug (CVE-2021-38003) against the ancient engine, then sideloaded a trojanized DLL beside a legitimate 7-Zip binary. GRAYRABBIT’s capabilities (per Gen / prior Google writeups) include process execution, reverse shells, file transfer, and reflective plugin loads. Gen does not publish a global victim count — underwrite Undisclosed; org totals: Undisclosed.
Disclosure: Gen reported to Tencent on Apr 9; auto-update fix 16.3.0.3498 confirmed Apr 21 (12-day turnaround). The patch hardens biz_helper.exe (HTTPS-only, allowlisted hostnames for URL switches). Gen notes the embedded CEF still ships outdated and unsandboxed — the front door is closed; the engine debt remains. Underwrite sheet: primary Gen Threat Labs; secondary BleepingComputer / SecurityWeek. Update Sogou now; hunt for crafted sgbiz: delivery and GRAYRABBIT IOCs Gen published.
