Impact
The flaw is a zero-click remote code execution vulnerability located in the Terminal/Notification.hs component of the SimpleX Chat application. By embedding a specially crafted text payload, an attacker can trigger the application to execute arbitrary system commands in the context of the running process. This grants unrestricted code execution, compromising confidentiality, integrity, and availability of the device and any data stored by the app.
Affected Systems
Any installation of SimpleX Chat that runs a version earlier than 6.5 is affected. The vulnerability has been confirmed only in the Terminal/Notification.hs module and impacts both mobile and desktop deployments that rely on that code path.
Risk and Exploitability
The CVSS score of 9.8 marks the issue as critical. The EPSS score of less than 1% indicates a low but non-zero likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers need only send the crafted text message—no user interaction or additional network access is required. Because the influence is application-wide, compromised devices could be leveraged for broader attacks or data exfiltration.
OpenCVE Enrichment