Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability
First reported
Last updated
Happening score
H score 89
1 unique sources, 1 articles

Summary

Hide ▲

Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the logged-in user's privileges. Gen Digital tied the bug to CVE-2026-51990 and said Tencent completed a fix for version 16.3.0.3498 in April 2026. The flaw was used in a live intrusion to deliver the GRAYRABBIT backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.

Cases

Related Happenings

UNC3569 Sogou Input Method exploitation campaign

Campaign
H score89 First: 11.09.2026 10:14 Last: 11.09.2026 10:14 Sources 1

How related: Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.

About this happening: The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...

Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw

Vulnerability
H score16 First: 20.08.2026 16:48 Last: 20.08.2026 16:48 Sources 1

About this happening: isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...

Timeline

  1. 11.09.2026 10:14 2 articles · 2h ago

    Gen Digital details UNC3569 Sogou Input Method exploitation and GRAYRABBIT delivery

    Technical Analysis Update

    Gen Digital published research on September 11, 2026 describing a UNC3569 campaign that used a crafted sgbiz: link against Sogou Input Method on Windows to install GRAYRABBIT and execute code with the logged-in user's privileges; the attack page also carried an exploit for CVE-2021-38003.

    Show sources