
Tencent patched the link into Sogou's hidden browser. The six-year-old engine, still unsandboxed, is still there
2026-09-15Security
Gen Threat Labs traced a China-linked intrusion to Sogou Input Method, where one click could open an embedded Chromium 80 engine running with its sandbox and same-origin policy switched off. The group used a 2021 Chrome exploit to install the GRAYRABBIT backdoor. Tencent closed the entry point in 12 days, but Gen says the browser component was not changed.