CVE-2026-52103
Received Received - Intake

Zero-Click RCE in SimpleX Chat

Vulnerability report for CVE-2026-52103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: MITRE

Description

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simplex chat 6.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a zero-click remote code execution (RCE) vulnerability in SimpleX Chat before version 6.5. It exists in the /Terminal/Notification.hs component and allows attackers to run arbitrary commands on the affected system without any user interaction. The attack occurs when a specially crafted payload is sent via a text message.

Impact Analysis

This vulnerability could allow attackers to take full control of your SimpleX Chat application without you doing anything. They could execute malicious commands, steal data, or install malware on your device. Since it requires no user interaction, even cautious users are at risk.

Compliance Impact

The vulnerability allows arbitrary command execution without user interaction, which could lead to unauthorized access to sensitive data. This may violate GDPR's data protection requirements and HIPAA's security rules for protected health information if exploited.

Mitigation Strategies

Update SimpleX Chat to version v6.5 or later to address the zero-click RCE vulnerability in the Terminal/Notification.hs component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart