← BACK TO FEED
TAG

chinese hackers1 article

Chinese Hackers Weaponised a Flaw in Tencent's Sogou to Drop a Backdoor on Hundreds of Millions of Potential Targets

A critical vulnerability (CVE-2026-51990) in Tencent's widely used Sogou Input Method was exploited by the Chinese threat actor UNC3569 to deploy the GrayRabbit backdoor via crafted one-click URLs. The flaw chained three weaknesses — unvalidated argument injection, unrestricted URL navigation, and an outdated, unpatched Chromium 80 browser engine — to achieve system-level code execution. Tencent issued a partial fix in version 16.3.0.3498, though the underlying Chromium configuration remains unaddressed.

15 Sept 2026