Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)
Vulnerability
Updated: 11.09.2026 10:14
· First: 11.09.2026 10:14
· 📰 2 src / 2 articles
· H score: 89
CVE-2026-51990 is a critical one-click RCE in Tencent’s Sogou Input Method for Windows that UNC3569 exploited through a crafted sgbiz: link to load a malicious page and deploy the GRAYRABBIT backdoor. Gen Digital said the chain used biz_helper.exe, SGMyInput.exe, and an outdated, unsandboxed Chromium 80 browser path with disabled web-security protections to reach code execution. Gen reported the issue to Tencent on April 9, 2026, and Tencent completed a fix in version 16.3.0.3498 on April 21, 2026. The patch validates protocol-handler URL arguments, allows only HTTPS, and restricts navigation to approved Sogou and Tencent domains, while the broader browser-engine weakness remained in place.