Security Update Recommendation for the Sogou Input Method Product
Sep 29 2026
Actual vulnerability attack cases exploiting a vulnerability in the Sogou Input Method have been confirmed.
The affected products are versions of the Sogou Input Method for Windows prior to 16.3.0.3498.
The resolved vulnerability is CVE-2026-51990, a remote code execution vulnerability caused by code injection in the biz_helper.Exe component. Remote code execution is a vulnerability that allows a threat actor to execute arbitrary code on the victim’s system.
The CVSS score for this vulnerability is 9.8.
A Vulnerability Patch has been provided via the latest update; users must update Sogou Input Method for Windows to version 16.3.0.3498 Or higher.
The reference site “Gray Rabbit’s One-Click Backdoor: Sogou CVE-2026-51990” has been provided.