Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Tencent, which owns Sogou
A critical vulnerability in Sogou Input Method, a widely used Chinese-language input editor for Windows, has been actively exploited by Chinese threat actors to execute arbitrary code remotely. The flaw, discovered in September 2026, allows attackers to trigger one-click code execution without user interaction beyond launching the software. This zero-click exploit has raised alarms due to its potential for stealthy infiltration and data theft. The vulnerability stems from improper memory handling within the input method’s processing engine, which fails to validate certain input sequences. Attackers can craft malicious inputs that, when processed by Sogou, execute shellcode with the privileges of the current user. Security researchers noted that the exploit does not require phishing or social engineering, making it particularly dangerous in targeted campaigns.
Breaking news:
Tencent, which owns Sogou, confirmed the issue after internal detection of anomalous activity linked to known Chinese APT groups. How the Exploit Bypasses Standard Defenses The attack leverages a use-after-free condition in Sogou’s candidate word prediction module, triggering when users type specific character combinations. Unlike traditional malware delivery, this method operates entirely within legitimate software processes, evading detection by conventional antivirus tools. Analysts observed that the exploit chain uses legitimate Windows APIs to escalate privileges after initial code execution, allowing persistent access to victim systems. The technique has been linked to espionage efforts targeting government and technology sectors in Asia and Europe. What Makes This Vulnerability Particularly Severe The severity is amplified by Sogou’s massive user base, with over 400 million monthly active users primarily in China and overseas Chinese communities.
Because the input method runs with high integrity levels and integrates deeply into the OS
Because the input method runs with high integrity levels and integrates deeply into the OS, exploitation can lead to full system compromise. Unlike browser-based flaws, this vulnerability affects offline functionality, meaning air-gapped or restricted networks are not immune if the software is present. Patches were delayed due to the complexity of rewriting legacy input handling code without breaking language support. Frequently Asked Questions How can users protect themselves if they use Sogou Input Method? Users should immediately update to the latest version of Sogou Input Method released after September 2026, which includes the security patch. Disabling the software or switching to an alternative input method is recommended until updates are applied. Is this exploit limited to Chinese-language systems? No, the vulnerability exists in the core input processing logic and can be triggered on any Windows system where Sogou is installed, regardless of language settings or regional configuration.
Why did it take so long to patch this flaw? The issue required significant changes to Sogou’s decades-old input engine, which must balance security with complex linguistic processing for Chinese characters, delaying deployment until thorough testing ensured compatibility.
More stories: