CVE-2026-51990 is a remote code-execution chain in Tencent Sogou Input Method for Windows. Its custom sgbiz: protocol handler validated the requested component but failed to validate an attacker-controlled parameter before passing it as command-line arguments to a legitimate Sogou process. An attacker could invoke the skin-marketplace webview with a supplied URL, which the application navigated to without scheme or origin validation. The webview used an obsolete Chromium 80/CEF build with Chromium sandboxing disabled and web-security protections disabled. In observed exploitation, a malicious page used CVE-2021-38003 in the embedded V8 engine to execute code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-line argument validation flaw in Sogou Input Method's handling of its custom sgbiz: protocol. Crafted links could redirect Sogou functionality to an attacker-controlled website and enable a compromise chain resulting in remote code execution and backdoor deployment.
A vulnerability in the Windows Sogou Input Method sgbiz: custom-protocol handler. Insufficient validation of command-line arguments allowed a crafted link to direct SGMyInput.exe's skin-store browser to an attacker-controlled URL. Because Sogou's embedded Chromium 80 browser has its sandbox and web-security protections disabled, the chain enabled user-level remote code execution through a browser exploit.
A one-click remote code-execution chain in Sogou Input Method. A crafted sgbiz: link injects arguments into SGMyInput.exe, causes its skincenter CEF webview to load an attacker-controlled URL, and exposes the victim to exploitation through its obsolete, unsandboxed Chromium 80 engine with web-security controls disabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.