Gray Rabbits and the Tale of a One-Click Backdoor
released on 2026-09-11 @ 09:00:36 AM
Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.