CyberRota Analysis
AI-GeneratedDesktopSMS 1.11.0 contains a vulnerability that allows local attackers to exploit the application's service to send and retrieve SMS messages without user interaction or pairing confirmation. This unauthorized access can lead to the compromise of sensitive SMS-derived content and the establishment of a persistent attacker-controlled identity. Organizations using this application should prioritize remediation to prevent potential data breaches and unauthorized communications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.