securityonline.info 14 Sept 2026, 00:00 UTC

Sogou Input Method Flaw Exposed Windows Users to Espionage Attacks

Sogou Input Method Flaw Exposed Windows Users to Espionage Attacks
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor
🇨🇳 UNC3569

SECURITY researchers at Gen Threat Labs report that a critical remote-code-execution flaw in Sogou Input Method, tracked as CVE-2026-51990, was exploited in the wild before it was patched. The software has hundreds of millions of desktop installations worldwide. Attackers could compromise a Windows computer through a single malicious link: the application’s protocol handler passed unsanitised command-line parameters to the program, which then opened an attacker-controlled page in an embedded Chromium browser.

That browser used a March 2020 engine, ran without its native sandbox and had key web security controls, including same-origin protections, disabled. The page exploited an older V8 memory-safety bug to execute code.

The activity has been attributed with moderate confidence to UNC3569, which Google describes as a China-nexus espionage group targeting government, education, finance and technology organisations in East and Southeast Asia. Investigators say compromised systems received the GRAYRABBIT backdoor, which provides interactive command shells, remote file management and support for loading plugins.

The deployment used a legitimate 7-Zip executable and a malicious DLL, relying on binary sideloading; the loader also checked for sandbox-like environments before decrypting the implant in memory.

Gen Threat Labs reported the vulnerability to Tencent on 9 April 2026, and Tencent released an update 12 days later. Users should upgrade Sogou Input Method to version 16.3.0.3498 or later. Researchers warn that the embedded browser remains outdated and unsandboxed, while organisations should restrict custom protocol handlers and monitor for unexpected processes or unauthorised DLLs in input-method directories.

View full article

Article by CyberSIXT