EXPLOITED

Sogou CVE-2026-51990 is a one-click RCE. UNC3569 used it to drop GRAYRABBIT.

Tencent’s Chinese IME — hundreds of millions of installs per Gen Digital — chained an unvalidated sgbiz: handler, unrestricted CEF navigation, and a sandbox-off Chromium 80 into remote code execution. Fixed build: 16.3.0.3498. Victim tally: Undisclosed.

Sep 14, 2026 · 3 min read

Gen Threat Labs (published Sep 10; amplified Sep 13–14 by BleepingComputer and SecurityWeek) reports CVE-2026-51990 in Tencent’s Sogou Input Method for Windows. A crafted sgbiz: link hands Windows to biz_helper.exe, which launches legitimate SGMyInput.exe with attacker-controlled arguments. The skincenter path opens a CEF webview and navigates to an attacker URL with no scheme or domain check. That webview runs Chromium 80 (≈ March 2020) with the sandbox disabled and same-origin protections stripped — so a single click can become user-privilege code execution.

Gen observed the chain in an active UNC3569 (PRC-nexus) intrusion delivering GRAYRABBIT, the modular backdoor Google Threat Intelligence has tied to that cluster. The exploit page used a Chromium V8 bug (CVE-2021-38003) against the ancient engine, then sideloaded a trojanized DLL beside a legitimate 7-Zip binary. GRAYRABBIT’s capabilities (per Gen / prior Google writeups) include process execution, reverse shells, file transfer, and reflective plugin loads. Gen does not publish a global victim count — underwrite Undisclosed; org totals: Undisclosed.

Disclosure: Gen reported to Tencent on Apr 9; auto-update fix 16.3.0.3498 confirmed Apr 21 (12-day turnaround). The patch hardens biz_helper.exe (HTTPS-only, allowlisted hostnames for URL switches). Gen notes the embedded CEF still ships outdated and unsandboxed — the front door is closed; the engine debt remains. Underwrite sheet: primary Gen Threat Labs; secondary BleepingComputer / SecurityWeek. Update Sogou now; hunt for crafted sgbiz: delivery and GRAYRABBIT IOCs Gen published.

Sources