CVE Tools

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

SecurityWeekBy Ionut Arghire

Reported exploitedSogou Input MethodUNC3569Tencent

Our summary

Chinese threat actors known as UNC3569 are actively exploiting a critical vulnerability in Tencent's Sogou Input Method to achieve one-click remote code execution. The exploit leverages CVE-2026-51990, chaining command-line injection with an unpatched Chromium 80 engine to deploy the GrayRabbit backdoor against victims. While the specific injection vector was fixed in version 16.3.0.3498, researchers note that the underlying browser engine remains vulnerable and unsandboxed.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store