Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-94540

HIGH NVD
CVSS Score 7.7
Severity HIGH
Published Sep 21, 2026
Vendor unknown

Description

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

References