CVE-2026-52103

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.

Published 2026-08-26. Last modified 2026-09-09.