CVE-2026-18604
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Summary
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| textPlus | Text Message and Call App | 8.3.0 | affected |
| textPlus | Text Message and Call App | 8.3.1 | affected |
| textPlus | Text Message and Call App | 8.3.2 | affected |
| textPlus | Text Message and Call App | 8.3.3 | affected |
| textPlus | Text Message and Call App | 8.3.4 | affected |
| textPlus | Text Message and Call App | 8.3.5 | affected |
Weaknesses
- CWE-926: Improper Export of Android Application Components
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
References
- https://vuldb.com/vuln/385527
- https://vuldb.com/vuln/385527/cti
- https://vuldb.com/cve/CVE-2026-18604
- https://vuldb.com/submit/851700
- https://github.com/actuator/com.gogii.textplus
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.