CVE-2026-51990

Sogou · Sogou Input Method

A remote code execution vulnerability in the biz_helper.exe component of Sogou Input Method allows unauthenticated attackers to execute arbitrary code.

Executive summary

Sogou Input Method contains a critical remote code execution vulnerability that allows unauthenticated attackers to compromise affected systems.

Vulnerability

This vulnerability resides in the biz_helper.exe component of the software. It allows an unauthenticated remote attacker to achieve arbitrary code execution on the host system with high impact to confidentiality, integrity, and availability.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code represents the highest level of system risk. Successful exploitation could lead to total system compromise, unauthorized data exfiltration, and the installation of persistent malware, posing a severe threat to business operations and data security. The CVSS score of 9.8 reflects the critical nature of this flaw and the potential for widespread impact.

Remediation

Immediate Action: Update Sogou Input Method to version 16.3.0.3498 or higher immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor network traffic for suspicious activity involving the biz_helper.exe process and review endpoint logs for unauthorized execution attempts or unexpected child processes.

Compensating Controls: Implement network segmentation and egress filtering to restrict unauthorized external communication from the affected component, thereby limiting the potential for an attacker to establish a command and control connection.

Exploitation status

Public Exploit Available: Yes, a public proof of concept is available via the GitHub repository linked in the enrichment data.

Analyst recommendation

Given the critical severity and the ease of exploitation, organizations must prioritize the immediate patching of all instances of Sogou Input Method. Failure to update the software exposes systems to complete remote takeover. Administrators should verify the version installed across their environment and enforce the update without delay to minimize the window of exposure.

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written

Sources