Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
A critical vulnerability in Sogou Input Method, a popular Chinese-language input method editor, has been exploited by a Chinese threat actor (UNC3569) to deploy the GrayRabbit backdoor. The vulnerability stems from a combination of flaws including unvalidated command-line argument injection and an outdated, un-sandboxed Chromium browser engine, allowing for one-click code execution and deployment of a persistent backdoor.
A critical vulnerability, tracked as CVE-2026-51990, exists within Sogou Input Method, a widely used Chinese-language input method editor for Windows. The vulnerability has been actively exploited by the Chinese threat actor UNC3569, who leverages it to deploy the GrayRabbit backdoor. This exploit chain combines several weaknesses, including unvalidated command-line argument injection and an outdated Chromium browser engine (version 80) lacking critical security patches and sandbox protections.
According to Gen Threat Labs, the issue arises because the protocol handler does not sanitize or validate the ‘param’ parameter during URL parsing. This allows an attacker to inject command-line arguments in a URL, directing the browser to a ‘skincenter’ page, which then executes a copy and navigation. The Chromium engine’s lack of updates and disabled sandbox further exacerbate the risk.
UNC3569 has been consistently observed using this exploit to target government, education, technology, and finance organizations globally. The GrayRabbit backdoor, a persistent backdoor consistently observed in UNC3569’s intrusions since at least 2021, provides attackers with a reverse shell, enabling them to execute processes, load plugins, write data to the interactive shell, upload files to a command-and-control (C&C) server, and collect system information.
Gen Threat Labs reported the vulnerability to Tencent on April 9, and a fix was implemented in Sogou Input Method version 16.3.0.3498, which utilizes an automatic update mechanism. However, the underlying Chromium configuration remains unchanged. As of September 10, the configuration and version have not been updated.
Related: AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force