Impact
A zero-click remote code execution flaw resides in the Terminal/Notification.hs module of SimpleX Chat. Attackers can craft a malicious payload within a text message that, when processed by the vulnerable version, causes the application to execute arbitrary system commands without user interaction. The impact is full code execution in the context of the application, compromising confidentiality, integrity, and availability of the device and any persisted data.
Affected Systems
SimpleX Chat before version 6.5. The vendor is SimpleX, a mobile and desktop messaging platform. Any installation of the application that has not been upgraded to v6.5 or later is susceptible.
Risk and Exploitability
The CVE lacks an EPSS score and is not listed in the CISA KEV catalog, but the nature of the flaw—zero-click arbitrary command execution—implies a high exploit risk. An attacker can trigger the vulnerability by sending a specially crafted message, requiring no user action and no network infrastructure beyond the standard messaging channel. Given the critical impact of remote code execution, the vulnerability warrants immediate attention.
OpenCVE Enrichment