CVE-2026-52103: SimpleX Chat vulnerability
Published Aug 26, 2026
·Updated
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
Affected Software
1 affected component
SimpleX Chat<6.5
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
SimpleX Chat installations running versions before v6.5 are exposed. The vulnerable component is /Terminal/Notification.hs.
2
What does an attacker need to exploit it?
An attacker needs to send a crafted payload in a text message. Exploitation requires no user interaction.
3
What is the impact of successful exploitation?
A successful exploit can execute arbitrary commands in the context of the SimpleX Chat application.
4
What version addresses the issue?
The issue affects versions before v6.5, so upgrading to v6.5 or later removes the affected version range described here.