Analysis: Tencent's Sogou Input Method, the top Chinese character inputting tool in China with 450M+ MAUs, had since-fixed data-leaking flaws in its encryption
We urge Sogou Input Method users to immediately update to the most recent version of the app (at least Windows version 13.7, Android version 11.26, or iOS version 11.25). X: @russellbrandom , @citizenlab , and @jsrailton X: Russell Brandom / @russellbrandom : This is quite an exchange, from the recent Citizen Lab report https://citizenlab.ca/... [image] @citizenlab : 🚨🚨➡️ NEW REPORT OUT > Imagine if someone read everything you type online. Our new report- “Please do not make it public”, analyzes Tencent's #Sogou Input Method, the most popular input app in #China has serious vulnerabilities in the encryption system. https://citizenlab.ca/... John Scott-Railton / @jsrailton : NEW RESEARCH: most popular Chinese keyboard app (450 million monthly users!) transmits every key typed to @TencentGlobal. My @citizenlab colleagues found vulnerable encryption means the uploaded keystrokes could *also* be intercepted by 3rd parties. 1/ https://citizenlab.ca/... [image]
Context & Ripple Effects
The report puts an input method—a layer that handles nearly every message and search—at the center of the privacy risk. It follows scrutiny of WeChat Mini Program tracking behavior, another Tencent-linked surface where routine use can generate sensitive behavioral data.
The concern is not isolated to one product: a later review of major pinyin keyboards found keystroke-exposure flaws across vendors. That makes secure transport and update adoption consequential beyond Sogou itself.
First-order effects
- Sogou users need current Windows, Android, or iOS releases to receive the fixes; unpatched users remain the immediately affected group.
- Tencent must remediate the encryption implementation and address the trust impact of a flaw that could expose typed text to Tencent and network interceptors.
Second-order effects
- Other keyboard vendors face stronger pressure to audit encryption paths and patch comparable weaknesses, particularly after the broader pinyin-keyboard findings.
- Organizations and users handling sensitive text may reassess keyboard-app update practices and the data exposure created by this otherwise invisible interface layer.
Third-order effects
- If recurring findings persist, Chinese-language input methods may become a distinct security-audit category rather than being treated as low-risk utility software.
- The pattern shifts privacy scrutiny from individual apps toward the shared infrastructure that captures user intent before messages, searches, or services process it.
The trend: This is part of a broader trend in which privacy and security risk is concentrating in ubiquitous interface software that observes users’ inputs at the point of entry.