CVE-2026-18604

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 17:16

Updated : 2026-08-12 21:00


NVD link : CVE-2026-18604

Mitre link : CVE-2026-18604

CVE.ORG link : CVE-2026-18604


JSON object : View

Products Affected

No product.

CWE
CWE-926

Improper Export of Android Application Components