CVE-2026-51990 sits in Sogou Input Method, Tencent's Windows keyboard app, and a China-aligned espionage group is using it to drop a backdoor called GrayRabbit. Sogou is not a niche product. It is a default input method on Windows machines across mainland China and much of the Chinese-speaking diaspora, which means the vulnerable population is not "Tencent users." It is anyone typing Chinese characters on a Windows box.
The mechanism matters more than the label. A local input method editor runs with deep hooks into every keystroke and every window the user touches, so a flaw that lets an outside actor plant code through it inherits that access for free. GrayRabbit does not need to phish a credential or exploit a browser. It rides a tool that Windows already trusts to sit in front of every application on the machine. For an APAC bank with mainland Chinese staff, contractors, or counterparties running Sogou on corporate endpoints, the exposure is not a hypothetical foreign app. It is a keyboard driver already sitting in the software inventory.
No patch status was disclosed in Tencent's advisory as of this writing. Until one lands, the only control that changes the outcome is application allowlisting that treats Sogou's update channel and installed binaries as untrusted by default, not endpoint detection tuned to catch GrayRabbit after it is already running.