VYPR

SimpleX Chat

by SimpleX Chat

CVEs (2)

  • CVE-2026-52103Aug 26, 2026
    risk 0.00cvss epss

    A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.

  • CVE-2022-45195MedNov 12, 2022
    risk 0.00cvss 5.3epss 0.01

    SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for…