According to Bleeping Computer, threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.Researchers at Gen Digital identified the vulnerability, tracked as CVE-2026-51990, as a one-click remote code execution flaw. The UNC3569 threat group is actively exploiting this issue by chaining three weaknesses: unvalidated command-line argument injection, unrestricted URL navigation, and an outdated, unsandboxed Chromium browser engine. The attack begins when a victim clicks a malicious link, triggering Sogou's protocol handler to pass attacker-controlled arguments to SGMyInput.exe. This leads to the embedded Chromium webview loading an attacker-controlled URL, which then exploits the outdated browser engine to achieve code execution and install the GrayRabbit backdoor.GrayRabbit is a modular malware family known to be used by UNC3569 for espionage and other malicious activities. Tencent has released a patch in version 16.3.0.3498, but the underlying browser engine remains a concern due to its outdated nature and lack of sandboxing.Source: Bleeping Computer
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
