# CVE-2026-18604

## Summary

- **CVE ID:** CVE-2026-18604
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-926
- **Published:** Aug 3, 2026
- **Last Modified:** Aug 3, 2026

## Description

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

## Affected Products

- textPlus — Text Message and Call App (8.3.0)
- textPlus — Text Message and Call App (8.3.1)
- textPlus — Text Message and Call App (8.3.2)
- textPlus — Text Message and Call App (8.3.3)
- textPlus — Text Message and Call App (8.3.4)
- textPlus — Text Message and Call App (8.3.5)

## References

- [CNA](https://vuldb.com/vuln/385527)
- [CNA](https://vuldb.com/vuln/385527/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-18604)
- [CNA](https://vuldb.com/submit/851700)
- [CNA](https://github.com/actuator/com.gogii.textplus)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._