A critical Sogou Input Method flaw allowed attackers to run code after a Windows user clicked a crafted link. Gen Threat Labs says the weakness affected software installed hundreds of millions of times and was exploited in real attacks.
A sandbox isolates browser content from the rest of the system. Disabling it did not remove every protection on the PC, but it meant a successful browser exploit could act with the signed-in user’s privileges.
The attack then downloaded and launched the GRAYRABBIT backdoor. The researchers said the whole initial exploit chain required no interaction beyond clicking the crafted link.
Who is affected
The issue, tracked as CVE-2026-51990, concerns the Windows version of Sogou Input Method, a widely used Chinese-language input method editor. It is especially relevant to people and organizations using the software in China.- Update Sogou Input Method through its official update mechanism or another trusted Tencent source.
- Treat unexpected links that ask to open Sogou components as suspicious, particularly those received through email, messages or webpages.
- Organizations should check whether affected systems launched Sogou’s configuration and web-rendering components after users opened unsolicited links.
Three weaknesses formed one exploit
According to Gen Threat Labs researcher Alexandru-Cristian Bardaș, the attack chained three problems. Sogou’s custom link handler accepted unchecked command-line arguments, its embedded web view could open an attacker-selected address, and that view used an old Chromium engine without its sandbox.A sandbox isolates browser content from the rest of the system. Disabling it did not remove every protection on the PC, but it meant a successful browser exploit could act with the signed-in user’s privileges.
Exploitation was observed
Gen Threat Labs traced the flaw while investigating an active intrusion attributed to UNC3569. In the observed campaign, a malicious page exploited a known V8 JavaScript engine vulnerability because Sogou bundled Chromium 80, an approximately March 2020 release.The attack then downloaded and launched the GRAYRABBIT backdoor. The researchers said the whole initial exploit chain required no interaction beyond clicking the crafted link.
Last edited by a moderator: