CVE-2026-18604
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.10%
- CWE
- CWE-926
- Published
- 2026-08-03
- Last modified
- 2026-08-03
Affected products
- textPlus Text Message and Call App
- textPlus Text Message and Call App
- textPlus Text Message and Call App
- textPlus Text Message and Call App
- textPlus Text Message and Call App
- textPlus Text Message and Call App
Weakness type
Related vulnerabilities
- CVE-2026-20516 — In MiracastService, there is a possible escalation of privilege due to a confused deputy. This...
- CVE-2026-44965 — Six Android App Widget configuration activities in the Datadog Android application are declared...
- CVE-2026-47363 — The launcher activity AppActivity in the Datadog Android application is declared...
- CVE-2026-47361 — BubbleChatActivity in the Datadog Android application is declared android:exported="true" with no...
- CVE-2026-20470 — In Telephony, there is a possible information disclosure due to a missing permission check. This...
- CVE-2026-57848 — Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
- CVE-2026-12960 — An Improper Export of Android Application Components vulnerability in ASUS Router App allows a...
- CVE-2026-54318 — Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location