CVE-2026-94540
HIGH
NVD
CVSS Score
7.7
Severity
HIGH
Published
Sep 21, 2026
Vendor
unknown
Description
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.