Sogou Input Method 'biz_helper' Remote Code Execution

Published September 10, 2026 CVE-2026-51990

Sogou Input Method contains a chain of three weaknesses that, if successfully exploited, could allow remote code execution. An attacker could exploit this vulnerability by convincing a user to click a specially crafted link.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmedLast checked today
Affects
Tencent+4 more
Exploited
Not confirmedNo confirmation recorded

Technical details

Affected software: Tencent, Sogou Input Method, Threat actor: UNC3569, Government, Education