Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Decline of migratory birds spurs calls for coordinated conservation
    • Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment
    • Did Trump say Republicans are ‘dumbest group of voters’ in 1998?
    • ‘Attacks will be fully autonomous’: Russia, Ukraine race towards AI warfare | Russia-Ukraine war News
    • Andy Burnham cancels engagements after death of father
    • Westminster’s time is coming to an end, say first ministers of UK’s Celtic nations | Devolution
    • The future of euro cash: trusted today, designed for tomorrow
    • Why are there concerns AI could threaten humanity?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical-severity vulnerability in Sogou Input Method has been exploited by a Chinese threat actor to deploy a backdoor, Gen Threat Labs reports.

    Developed by Tencent, Sogou Input Method is one of the most popular Chinese-language input method editors (IMEs) for Windows and is used by hundreds of millions of users.

    It is a collection of executables that communicate using a custom protocol scheme named sgbiz. When a URL is opened, the protocol handler (biz_helper.exe) parses the URL and dispatches it to the appropriate component.

    The critical flaw, tracked as CVE-2026-51990, chained three security weaknesses in a one-click exploit: unvalidated command-line argument injection, unrestricted URL navigation, and an outdated, un-sandboxed Chromium browser engine.

    According to Gen Threat Labs, the first issue existed because, during URL parsing, the protocol handler did not sanitize or validate the ‘param’ parameter, which controls the command-line arguments passed to the executable.

    This allowed an attacker to inject command-line arguments in the URL to declare a ‘skincenter’ page, which another function would simply copy and navigate the browser to.

    Advertisement. Scroll to continue reading.

    The next security hole goes deeper: the browser in Sogou Input Method is based on a Chromium 80 iteration released in March 2020 that is missing roughly six years of security patches, has the sandbox completely disabled, strips additional protections (including same-origin policy), and allows URLs to read other local files.

    The China-linked threat actor UNC3569 used this exploit chain to send crafted sgbiz URLs to unsuspecting victims. Once clicked, the exploit provided the attackers with system-level code execution.

    “We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GrayRabbit backdoor through a crafted link,” Gen Threat Labs says.

    Potentially linked to Chinese private contractor company i-SOON, UNC3569 is known for exploiting vulnerabilities in popular software to attack government, education, technology, and finance organizations globally.

    The GrayRabbit backdoor, which has been consistently observed across the threat actor’s intrusions since at least 2021, provides attackers with a reverse shell and can execute processes, load plugins, write data to the interactive shell, upload files to its command-and-control (C&C) server, collect system information, and terminate itself.

    Gen Threat Labs reported CVE-2026-51990 to Tencent on April 9. The security defect was addressed in Sogou Input Method version 16.3.0.3498, which was rolled out to all users via the automatic update mechanism.

    The fix added a check for URL-bearing switches in the protocol handler, but left the underlying Chromium configuration unchanged. According to Gen Threat Labs, as of September 10, the configuration and version have not been updated.

    Related: AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

    Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force

    Related: Chinese Hackers Target Medical, Military, and AI Research in North America

    Chinese Code critical Execution exploit Flaw hackers OneClick software Tencent
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Webinar: How malicious OAuth apps can lead to Google Workspace breaches

    CISOs Race to Control AI Agents Without Destroying Their Value

    What the 3M ChatGPT case reveals about AI governance

    Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    Microsoft: September updates break audio on some Windows PCs

    Symbiosis bridge exploit: 15 BTC recovered, LP terms pending

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026

    ‘Attacks will be fully autonomous’: Russia, Ukraine race towards AI warfare | Russia-Ukraine war News

    September 14, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.