CVE-2026-94540: DesktopSMS 1.11.0 Unauthorized Access via Local Service
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users running DesktopSMS 1.11.0 on a device where an attacker can execute code locally are exposed. The attacker reaches the application's service through the same-device loopback interface and uses the victim application's SMS permissions.
Does exploitation require the victim to approve pairing or interact with the attacker?
No. The local service accepts the attacker-selected paired identity without pairing confirmation or other user interaction.
What can an attacker do through the exposed service?
A local attacker can send SMS messages, retrieve SMS-derived content, and persist an attacker-selected paired identity. Confidentiality and integrity impact are rated high, while availability impact is not indicated.