Description
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A zero-click remote code execution flaw resides in the Terminal/Notification.hs module of SimpleX Chat. Attackers can craft a malicious payload within a text message that, when processed by the vulnerable version, causes the application to execute arbitrary system commands without user interaction. The impact is full code execution in the context of the application, compromising confidentiality, integrity, and availability of the device and any persisted data.

Affected Systems

SimpleX Chat before version 6.5. The vendor is SimpleX, a mobile and desktop messaging platform. Any installation of the application that has not been upgraded to v6.5 or later is susceptible.

Risk and Exploitability

The CVE lacks an EPSS score and is not listed in the CISA KEV catalog, but the nature of the flaw—zero-click arbitrary command execution—implies a high exploit risk. An attacker can trigger the vulnerability by sending a specially crafted message, requiring no user action and no network infrastructure beyond the standard messaging channel. Given the critical impact of remote code execution, the vulnerability warrants immediate attention.

Generated by OpenCVE AI on August 26, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SimpleX Chat to version 6.5 or later.
  • If an upgrade is not immediately possible, disable terminal notifications or isolate the Terminal/Notification.hs component so that incoming texts are not processed by the vulnerable code.
  • Inspect and sanitize inbound messages for suspicious patterns and monitor the application’s process list for unexpected command execution.

Generated by OpenCVE AI on August 26, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Zero‑Click Remote Code Execution via Crafted Text Message in SimpleX Chat
Weaknesses CWE-78

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T20:39:56.988Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T21:16:38.340

Modified: 2026-08-26T21:16:38.340

Link: CVE-2026-52103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')