Sceawere

Vulnerability Detail

CVE-2026-94540UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DesktopSMS Unauthorized Local Service Access

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
4h ago
Vendor
MrPear
Product
DesktopSMS
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-09-21T22:17:00.800Z",
  "pubdate": "2026-09-21T22:17:00.800Z",
  "executiveSummary": "DesktopSMS 1.11.0 is affected by an unauthorized access vulnerability within its local service component.\nThis vulnerability allows a local attacker to interact with the application's service without prior pairing or user authorization.\nBy leveraging same-device loopback communication, an attacker can hijack the application's permissions to perform unauthorized SMS operations.\nThe primary risk involves the unauthorized transmission of SMS messages, the retrieval of sensitive SMS-derived content, and the persistence of an attacker-controlled paired identity.\nThe vulnerability does not require network access, as it is restricted to local exploitation on the host device.\nThis flaw presents a significant security concern regarding the confidentiality and integrity of SMS communications handled by the application.",
  "technicalDetails": "The vulnerability stems from the improper implementation of inter-process communication (IPC) or service exposure within the DesktopSMS 1.11.0 local service.\nThe application exposes a local service that fails to enforce authentication or authorization checks when receiving requests from other processes on the same device.\nThe root cause is the lack of a secure pairing mechanism or validation of the calling process identity, allowing any local application or malicious actor with local execution capabilities to interface directly with the service.\nExploitation is achieved through same-device loopback communication. By sending malformed or unauthorized requests to the application's local service port or interface, an attacker can bypass the intended user-pairing flow.\nThe attack flow proceeds as follows: 1) The attacker identifies the exposed local service used by DesktopSMS; 2) The attacker crafts a request mimicking legitimate pairing or operational commands; 3) The service processes the request without verification, treating the attacker's process as a trusted entity; 4) The attacker persists their own identity within the service, effectively becoming a legitimate 'paired' partner.\nOnce the attacker successfully interacts with the service, they gain the ability to leverage the application's elevated permissions.\nThe impact includes the ability to transmit SMS messages using the victim's device, intercept or retrieve SMS-derived content (such as 2FA codes, account recovery tokens, or private communications), and maintain long-term access by persisting an attacker-selected paired identity.\nBecause the service accepts these commands without user interaction or visual feedback, the victim remains unaware that their messaging permissions are being utilized by an unauthorized third party.\nThe vulnerability is restricted to local attack vectors, meaning the attacker must be able to execute code locally on the device, such as through a secondary malicious application, to trigger the loopback communication."
}
CVE-2026-94540: DesktopSMS Unauthorized Local Service Access (HIGH Severity, CVSS: 7.7) | Sceawere