Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)
Vulnerability
Summary
Hide ▲
Show ▼
Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the logged-in user's privileges. Gen Digital tied the bug to CVE-2026-51990 and said Tencent completed a fix for version 16.3.0.3498 in April 2026. The flaw was used in a live intrusion to deliver the GRAYRABBIT backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.
Cases
Related Happenings
UNC3569 Sogou Input Method exploitation campaign
Campaign
H score89
First: 11.09.2026 10:14
Last: 11.09.2026 10:14
Sources 1
How related:
Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.
About this happening:
The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...
UNC3569 Sogou Input Method exploitation campaign
CampaignHow related: Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.
About this happening: The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...
Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw
Vulnerability
H score16
First: 20.08.2026 16:48
Last: 20.08.2026 16:48
Sources 1
About this happening:
isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...
Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw
VulnerabilityAbout this happening: isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...
Timeline
-
11.09.2026 10:14 1 articles · 2h ago
Gen Digital reports Sogou Input Method flaw to Tencent
Initial DisclosureGen Digital reported the Sogou Input Method Windows flaw to Tencent on April 9, 2026 after investigating a live intrusion tied to UNC3569; the issue is tracked as CVE-2026-51990.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 10:14 1 articles · 2h ago
Tencent completes Sogou Input Method fix and automatic update
Mitigation Patch UpdateTencent confirmed on April 21, 2026 that a fix for Sogou Input Method version 16.3.0.3498 was complete and would reach users through automatic update.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 10:14 2 articles · 2h ago
Gen Digital details UNC3569 Sogou Input Method exploitation and GRAYRABBIT delivery
Technical Analysis UpdateGen Digital published research on September 11, 2026 describing a UNC3569 campaign that used a crafted sgbiz: link against Sogou Input Method on Windows to install GRAYRABBIT and execute code with the logged-in user's privileges; the attack page also carried an exploit for CVE-2021-38003.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14