CVE-2026-18604

Summary

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

Affected Software

VendorProductVersion RangeStatus
textPlusText Message and Call App8.3.0affected
textPlusText Message and Call App8.3.1affected
textPlusText Message and Call App8.3.2affected
textPlusText Message and Call App8.3.3affected
textPlusText Message and Call App8.3.4affected
textPlusText Message and Call App8.3.5affected

Weaknesses

  • CWE-926: Improper Export of Android Application Components

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References