Researchers at Gen Digital’s Gen Threat Labs have identified active exploitation of a critical vulnerability, tracked as CVE-2026-51990, in Tencent’s Sogou Input Method for Windows. The flaw is being used by a China-aligned espionage group to deploy a backdoor known as GrayRabbit.

Sogou Input Method is a widely used Windows application that enables typing Chinese characters on a standard keyboard. It includes a custom link handler and an embedded web browser built on an outdated Chromium engine. Tencent’s product reportedly has hundreds of millions of installations across China.

According to Gen Threat Labs, the threat group tracked as UNC3569 exploited the vulnerability as a one-click remote code execution chain through a crafted link. The attack combines three separate weaknesses:

  • Unvalidated command-line argument injection in the app’s sgbiz: custom URI
  • Unrestricted URL navigation inside a CEF-based webview component
  • An outdated, unsandboxed Chromium browser engine (version 80) running with security protections disabled

The attack begins when a victim clicks a malicious sgbiz: link, which triggers Windows to launch Sogou’s biz_helper.exe protocol handler. That handler passes attacker-controlled arguments to the legitimate SGMyInput.exe executable without validation. The injected arguments open Sogou’s skincenter component and force its embedded Chromium webview to load an attacker-controlled URL, since Sogou does not restrict the destination or scheme. A malicious page then exploits the outdated Chromium engine, which runs unsandboxed, to achieve code execution and install GrayRabbit.

Google researchers previously described GrayRabbit in 2024 as a modular malware family tied to UNC3569, a China-based actor operating in both cybercrime and contractor-for-hire capacities. The sample analyzed by Gen Threat Labs is a more mature 64-bit variant with an expanded command set and RC4-encoded C2 configuration. Its capabilities include process execution, interactive reverse shells, file upload and download, system and user reconnaissance, and reflective in-memory plugin loading.

Gen Threat Labs reported the vulnerability to Tencent on April 9, and the company shipped a fix in Sogou Input Method version 16.3.0.3498 on April 21. The patch validates protocol handler arguments, restricts navigation to HTTPS, and limits destinations to approved Sogou and Tencent domains.

Researchers caution, however, that the underlying Chromium engine remains outdated and still runs unsandboxed with several web security protections disabled, leaving room for future exploitation of the browser component.