LIVE · cybersecurity feed
Live wire
CVE-2026-51990critical

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

zeroday.news ·

Threat actors identified as UNC3569, a group suspected of operating on behalf of China, have been observed actively exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows. The flaw, tracked as CVE-2026-51990, is a one-click remote code execution (RCE) vulnerability that allows attackers to deploy the GrayRabbit backdoor.

Sogou Input Method is a widely used Windows application, particularly popular in China, designed to facilitate typing Chinese characters. It includes a custom link handler and an embedded web browser that utilizes an outdated Chromium engine.

The attack chain, as detailed by cybersecurity researchers, leverages three distinct weaknesses within the Sogou Input Method product. It begins with an unvalidated command-line argument injection vulnerability found in the `sgbiz:` URI scheme. This is followed by unrestricted URL navigation capabilities within a Chromium Embedded Framework (CEF)-based webview. The final component is the use of an outdated and unsandboxed Chromium browser engine.

When a victim clicks a specially crafted `sgbiz:` custom URI, Windows invokes Sogou's `biz_helper.exe` protocol handler. This handler then passes attacker-controlled command-line arguments to the legitimate `SGMyInput.exe` executable without proper validation. These injected arguments are designed to open Sogou's `skincenter` component and instruct its embedded Chromium webview to load a URL controlled by the attacker. Crucially, Sogou does not impose restrictions on the scheme or destination of this URL.

In the third stage of the attack, a malicious web page exploits a known vulnerability within Sogou's outdated Chromium 80 engine. Since this browser runs without a sandbox and with several important web-security protections disabled, the exploit successfully achieves code execution on the victim's system, leading to the installation of the GrayRabbit backdoor.

GrayRabbit, first described by Google researchers in 2024, is a modular malware family previously linked to UNC3569. The variant analyzed by researchers is a more advanced 64-bit version, featuring an expanded command set and RC4-encoded command-and-control (C2) configuration. Its capabilities include executing processes, establishing interactive reverse shells, uploading and downloading files, gathering system and user information, and reflectively loading plugins into the host's memory.

Researchers reported their findings to Tencent on April 9. Tencent subsequently released a fix in Sogou Input Method version 16.3.0.3498 on April 21. This patch addresses the vulnerability by validating the URL arguments accepted through the protocol handler, restricting navigation to approved domains related to Sogou and Tencent, and permitting only HTTPS. However, researchers noted that the underlying browser component remains outdated and continues to operate without a sandbox, with many web security protections still disabled.

vulnerabilities in this storyCVE-2026-51990
vulnerabilitymalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice