{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mrpear/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mrpear:desktopsms:1.11.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-94540"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DesktopSMS (1.11.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MrPear"],"content_html":"\u003cp\u003eDesktopSMS version 1.11.0, developed by MrPear, is susceptible to an unauthorized access vulnerability within its local service component. The flaw enables a local attacker to interact with the application's service without requiring valid pairing confirmation or user interaction. By leveraging the same-device loopback interface, an attacker can bypass existing authentication controls to transmit SMS messages, exfiltrate SMS-derived content, and persist an attacker-selected paired identity. This allows the attacker to conduct privileged SMS operations using the security context and permissions of the DesktopSMS application. Because this requires local access to the device to interface with the loopback service, it is a significant concern for multi-user environments or systems where local access by untrusted actors is a threat.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to hijack the SMS capabilities of the DesktopSMS application. Impact includes unauthorized message transmission, interception of sensitive SMS-based content (such as two-factor authentication codes), and long-term persistence of a rogue identity within the application's pairing configuration. This can lead to account takeover or information disclosure for services protected by SMS verification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview all endpoints for the presence of DesktopSMS version 1.11.0.\u003c/li\u003e\n\u003cli\u003eIf the application is not business-critical, uninstall it from all workstations to remove the attack surface.\u003c/li\u003e\n\u003cli\u003eRestrict local user permissions on systems where DesktopSMS is required to prevent unauthorized process interaction.\u003c/li\u003e\n\u003cli\u003eMonitor for updates from MrPear and apply patches immediately upon release to address CVE-2026-94540.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-21T22:30:51Z","date_published":"2026-09-21T22:30:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-desktopsms-unauthorized-access/","summary":"DesktopSMS version 1.11.0 contains a local service vulnerability allowing an unauthenticated attacker to bypass pairing and perform unauthorized SMS operations via loopback communication.","title":"Unauthorized Access Vulnerability in DesktopSMS","url":"https://feed.craftedsignal.io/briefs/2026-09-desktopsms-unauthorized-access/"}],"language":"en","title":"CraftedSignal Threat Feed - MrPear","version":"https://jsonfeed.org/version/1.1"}