{"id":"CVE-2026-94540","published":"2026-09-21T22:17:00.800","lastModified":"2026-09-21T22:17:00.800","description":"DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.","cvssScore":7.7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://github.com/actuator/net.mrpear.apps.desktopsmslite","tags":[]},{"url":"https://www.vulncheck.com/advisories/desktopsms-unauthorized-access-via-local-service","tags":[]}],"exploitRefs":[{"url":"https://github.com/actuator/net.mrpear.apps.desktopsmslite","tags":[]}],"hasPoc":true,"ai":{"summary":"DesktopSMS 1.11.0 allows local attackers to transmit and retrieve SMS content without user interaction due to an unauthorized access vulnerability.","exploitability":"Exploitation is relatively easy as it requires only local access to the application's unauthenticated service.","blast_radius":"If exploited, this could lead to unauthorized control over SMS operations on the victim’s device, potentially compromising sensitive information.","remediation":"Update DesktopSMS to the latest version or apply vendor-provided patches immediately.","tags":["auth-bypass","sms","local-attack","privilege-elevation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:10:48.683Z"}}