A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://te.mpe.st/disclosures/20260510-simplex.html |
|
History
Wed, 02 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Zero-Click Remote Code Execution via Crafted Text Message in SimpleX Chat Terminal Notifications |
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Zero‑Click Remote Code Execution via Crafted Text Message in SimpleX Chat | |
| Weaknesses | CWE-78 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Zero‑Click Remote Code Execution via Crafted Text Message in SimpleX Chat | |
| Weaknesses | CWE-78 |
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-26T00:00:00.000Z
Updated: 2026-09-01T18:49:43.731Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-52103
Updated: 2026-09-01T18:49:38.261Z
Status : Deferred
Published: 2026-08-26T21:16:38.340
Modified: 2026-09-09T16:04:24.933
Link: CVE-2026-52103
No data.