Unauthorized Access Vulnerability in DesktopSMS
DesktopSMS version 1.11.0 contains a local service vulnerability allowing an unauthenticated attacker to bypass pairing and perform unauthorized SMS operations via loopback communication.
CVE search metadata
CVE search record: CVE-2026-94540. Severity: high. CVSS: 7.7. KEV: no. Product: DesktopSMS (1.11.0). Brief: Unauthorized Access Vulnerability in DesktopSMS. Brief link: https://feed.craftedsignal.io/briefs/2026-09-desktopsms-unauthorized-access/
DesktopSMS version 1.11.0, developed by MrPear, is susceptible to an unauthorized access vulnerability within its local service component. The flaw enables a local attacker to interact with the application's service without requiring valid pairing confirmation or user interaction. By leveraging the same-device loopback interface, an attacker can bypass existing authentication controls to transmit SMS messages, exfiltrate SMS-derived content, and persist an attacker-selected paired identity. This allows the attacker to conduct privileged SMS operations using the security context and permissions of the DesktopSMS application. Because this requires local access to the device to interface with the loopback service, it is a significant concern for multi-user environments or systems where local access by untrusted actors is a threat.
Impact
Successful exploitation allows a local attacker to hijack the SMS capabilities of the DesktopSMS application. Impact includes unauthorized message transmission, interception of sensitive SMS-based content (such as two-factor authentication codes), and long-term persistence of a rogue identity within the application's pairing configuration. This can lead to account takeover or information disclosure for services protected by SMS verification.
Recommendation
- Review all endpoints for the presence of DesktopSMS version 1.11.0.
- If the application is not business-critical, uninstall it from all workstations to remove the attack surface.
- Restrict local user permissions on systems where DesktopSMS is required to prevent unauthorized process interaction.
- Monitor for updates from MrPear and apply patches immediately upon release to address CVE-2026-94540.
Immediate actions
Inventory systems for DesktopSMS 1.11.0
Mitigations
Remove or disable DesktopSMS 1.11.0
CVE-2026-94540