Hackers Exploit Critical RCE Flaw in Tencent’s Sogou Input Method (CVE‑2026‑51990) to Deploy GrayRabbit Backdoor
What It Is – A one‑click remote code execution vulnerability (CVE‑2026‑51990) in Tencent’s Sogou Input Method for Windows allows an attacker to run arbitrary code via a crafted sgbiz: URI. The flaw is being actively exploited by the UNC3569 espionage group to install the GrayRabbit modular backdoor.
Exploitability – The vulnerability is confirmed in the wild; a public proof‑of‑concept exists. CVSS is not published, but the vendor classifies it as critical (remote code execution with no user interaction beyond clicking a link).
Affected Products – Tencent Sogou Input Method for Windows (all versions prior to 16.3.0.3498).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability‑management controls that capture discovery, remediation, and verification evidence across third‑party software.
- Highlights gaps in protocol‑handler validation and webview sandboxing, which are control areas mapped to many frameworks (e.g., NIST CSF, ISO 27001).
- Provides a concrete example of why enterprises must maintain auditable proof of patch deployment for widely‑installed client applications.
Recommended Actions
- Inventory all endpoints running Sogou Input Method and verify version 16.3.0.3498 or later is deployed.
- If the product is not required, consider removal to eliminate the attack surface.
- Update your vulnerability‑management process to capture protocol‑handler validation as a control evidence point.
- Conduct a focused control‑mapping review to ensure patch‑management evidence is continuously collected for third‑party components.
Source: BleepingComputer – Hackers exploit Tencent app flaw to deploy GrayRabbit malware