Gray Rabbits and the Tale of a One-Click Backdoor

Published September 11, 2026 CVE-2021-38003

Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020.

Report priority
High
Affected versions
unspecified to before 95.0.4638.69
Targets
Chrome

Technical details

Affected software: Chromeby Google