high · CVSS v3 7.7 · CVSS v4 7.4
CVE-2026-94540
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, r…
Description
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.
Scores
- Severity
- high
- CVSS v2
- 6.6
- CVSS v3
- 7.7
- CVSS v4
- 7.4
- EPSS
- —