Tencent Sogou Input Method Vulnerability Exploited: Early Warning
- Severity
- HIGH
- Affected component
- tencent sogou input method (npm)
- Patched version
- Not yet available
An early warning indicates that a critical vulnerability in Tencent's Sogou Input Method for Windows is being exploited to deploy the GrayRabbit backdoor. Users of this application are advised to take immediate precautions.
What happened
Threat actors reportedly linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows. This vulnerability allows for one-click remote code execution (RCE). Researchers at Gen Digital have observed this security issue being actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. Sogou Input Method, a popular Windows application for typing Chinese characters, is developed by Chinese tech giant Tencent and is widely used in China.
The application includes a custom link handler and a built-in web browser using an outdated Chromium engine. Given the widespread use of Sogou Input Method, the exploitation of this vulnerability poses a significant risk to affected systems. Users should monitor their systems for any signs of the GrayRabbit backdoor and stay informed about updates from Tencent regarding a patch for this vulnerability.
What to do about it
- Monitor your systems for any signs of the GrayRabbit backdoor.
- Stay informed about updates from Tencent regarding a patch for the vulnerability.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
tencent sogou input method is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Tencent's Sogou Input Method for Windows, you may be affected. The specific version range is not yet published.
What should I do right now?
Monitor your systems for any signs of the GrayRabbit backdoor and stay informed about updates from Tencent regarding a patch for the vulnerability.
Has this been exploited in the wild?
Yes, the vulnerability is reportedly being exploited in the wild by the UNC3569 threat group.