A critical vulnerability in Tencent’s Sogou Input Method for Windows has been exploited in the wild by a China-linked threat actor, according to Gen Threat Labs. The software is a widely used Chinese-language input method editor, reportedly installed by hundreds of millions of users. The flaw, tracked as CVE-2026-51990, affects the application’s custom `sgbiz` URL protocol and combines command-line argument injection, unrestricted URL navigation and an outdated, unsandboxed Chromium browser engine.
Attackers linked to UNC3569 sent victims specially crafted `sgbiz` links. Clicking one could trigger system-level code execution and install the GrayRabbit backdoor. Gen Threat Labs said GrayRabbit has been seen in the group’s intrusions since at least 2021 and supports reverse-shell access, process execution, plugin loading, file uploads to command-and-control infrastructure and system-information collection. UNC3569 is known for targeting government, education, technology and financial organisations, and may be associated with Chinese contractor i-SOON.
Gen Threat Labs reported the vulnerability to Tencent on 9 April. Tencent addressed the exploit chain in Sogou Input Method version 16.3.0.3498, distributed through automatic updates. However, the fix only added validation for URL-bearing switches in the protocol handler; the underlying Chromium component remained based on a March 2020 Chromium 80 release, with its sandbox and other protections disabled. Gen Threat Labs said this configuration and version were still unchanged as of 10 September.
Users and organisations should therefore verify that Sogou Input Method is at least version 16.3.0.3498 and investigate suspicious links or signs of GrayRabbit activity.