rootpwn

high · CVSS v3 7.7 · CVSS v4 7.4

CVE-2026-94540

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, r…

Description

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

Scores

Severity
high
CVSS v2
6.6
CVSS v3
7.7
CVSS v4
7.4
EPSS

← All CVEs