CVE-2026-94540: DesktopSMS 1.11.0 Unauthorized Access via Local Service

Published Sep 21, 2026
·
Updated

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

Affected Software

1 affected component
MrPear DesktopSMS=1.11.0

Event History

Sep 21, 2026
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Users running DesktopSMS 1.11.0 on a device where an attacker can execute code locally are exposed. The attacker reaches the application's service through the same-device loopback interface and uses the victim application's SMS permissions.

2

Does exploitation require the victim to approve pairing or interact with the attacker?

No. The local service accepts the attacker-selected paired identity without pairing confirmation or other user interaction.

3

What can an attacker do through the exposed service?

A local attacker can send SMS messages, retrieve SMS-derived content, and persist an attacker-selected paired identity. Confidentiality and integrity impact are rated high, while availability impact is not indicated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203