NPM · SEPTEMBER 2026 · EARLY WARNING

Tencent Sogou Input Method Vulnerability Exploited: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
tencent sogou input method (npm)
Patched version
Not yet available
CVE-2026-51990

An early warning indicates that a critical vulnerability in Tencent's Sogou Input Method for Windows is being exploited to deploy the GrayRabbit backdoor. Users of this application are advised to take immediate precautions.

What happened

Threat actors reportedly linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows. This vulnerability allows for one-click remote code execution (RCE). Researchers at Gen Digital have observed this security issue being actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. Sogou Input Method, a popular Windows application for typing Chinese characters, is developed by Chinese tech giant Tencent and is widely used in China.

The application includes a custom link handler and a built-in web browser using an outdated Chromium engine. Given the widespread use of Sogou Input Method, the exploitation of this vulnerability poses a significant risk to affected systems. Users should monitor their systems for any signs of the GrayRabbit backdoor and stay informed about updates from Tencent regarding a patch for this vulnerability.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If tencent sogou input method is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Tencent's Sogou Input Method for Windows, you may be affected. The specific version range is not yet published.

What should I do right now?

Monitor your systems for any signs of the GrayRabbit backdoor and stay informed about updates from Tencent regarding a patch for the vulnerability.

Has this been exploited in the wild?

Yes, the vulnerability is reportedly being exploited in the wild by the UNC3569 threat group.

Sources

Join the 0Day waitlist →

← Back to all threats