Skip to content
cve — cve-2026-51990

grep -rl "CVE-2026-51990" ./articles

CVE-2026-51990

Gen Threat Labs traced a China-linked intrusion to Sogou Input Method, where one click could open an embedded Chromium 80 engine running with its sandbox and same-origin policy switched off. The group used a 2021 Chrome exploit to install the GRAYRABBIT backdoor. Tencent closed the entry point in 12 days, but Gen says the browser component was not changed.

1 article — 2026-09-15

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered