Cybersecurity

Sogou Flaw Let One Click Backdoor an App Used by 455M a Month

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
Photo: Gen Digital
0 0
XWhatsAppTelegramLinkedIn

A single crafted link was enough to plant a backdoor on a Windows machine running Sogou Input Method, the Chinese typing tool owned by Tencent. Gen Digital's Gen Threat Labs detailed the flaw, tracked as CVE-2026-51990, in research published on 13 September 2026, and said it found the bug while examining a live intrusion rather than in a lab.

The researchers attribute that intrusion to UNC3569. The Hacker News reports that Google Threat Intelligence ties the group to China and places it within the country's hacker-for-hire scene, and that it has targeted government, education, technology and finance organisations mainly in East and Southeast Asia since 2021. SecurityWeek adds that the group has been described as potentially linked to the Chinese contractor firm i-SOON. The group is not being described as state-directed.

What makes the case unusual is that no single bug did the work. According to Gen Digital, the exploit chained three weaknesses: command-line arguments passed to the sgbiz: protocol handler without validation, unrestricted URL navigation inside a CEF-based webview, and a Chromium engine from around March 2020, version 80, running with its sandbox and same-origin policy switched off. Against that engine the attackers used CVE-2021-38003, a V8 type-confusion flaw that Chrome patched years ago. The Hacker News notes that at least 32 of 41 catalogued V8 flaws were fixed in Chrome releases newer than the version Sogou shipped.

The payload was GrayRabbit. Gen Digital describes an implant that can execute processes silently, open interactive reverse shells, load plugin modules into memory, collect system information and upload local files to a command-and-control server, communicating over raw TCP sockets with RC4 encryption.

The exposure figure is what gives the chain its weight. Gen Digital says Sogou Input Method has hundreds of millions of users; The Hacker News puts it at more than 455 million people a month, roughly 70 percent of Chinese input-method users across Windows, Android and iOS.

Users of the app do not need to act now. Gen Threat Labs reported the flaw to Tencent on 9 April 2026, and Tencent shipped a fix on 21 April 2026 in version 16.3.0.3498, delivered by automatic update; the patch validates URL arguments, allows only HTTPS and limits navigation to approved domains. MITRE assigned the CVE on 10 July 2026.

Two things are still open. Neither Gen Digital nor Tencent has published how many people were actually hit by GrayRabbit through this chain, so the 455 million figure describes the install base, not victims. And SecurityWeek reported that as of 10 September the underlying Chromium version and configuration had not been updated, meaning the specific entry point was closed while the aged engine beneath it remains.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.