CVE-2026-52103
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
- Published Aug 26, 2026
- CVSS 9.8 critical
- 1.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available