CVE Tools

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

BleepingComputerBy Bill Toulas

Reported exploitedSogou Input MethodUNC3569

Our summary

China-linked threat group UNC3569 is actively exploiting a critical one-click remote code execution vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. By chaining multiple weaknesses in the application's custom URI handling and outdated embedded Chromium browser, attackers successfully install the GrayRabbit backdoor on victim systems.

Gen Threat Labs confirmed the campaign involves executing malicious commands through an unvalidated sgbiz: link, which ultimately bypasses security controls due to the lack of sandboxing in the bundled browser engine. While Tencent released a patch in version 16.3.0.3498 that restricts URL schemes to HTTPS and approved domains, the underlying outdated browser architecture remains vulnerable.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store