CVE-2026-18604
Received Received - Intake

Improper Export of Android App Components in textPlus Text Message and Call App

Vulnerability report for CVE-2026-18604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulDB

Description

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gogii textplus to 8.3.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-926 The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the textPlus Text Message and Call App up to version 8.3.5 on Android. It involves improper export of Android application components in the DialerActivity function, allowing local attacks. An exploit is publicly available.

Detection Guidance

This vulnerability involves improper export of Android application components in textPlus up to version 8.3.5. Detection requires checking installed app versions and exported components. Use 'adb shell pm list packages -f' to list apps and their APK paths, then inspect the textPlus app manifest for exported activities or services. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to access sensitive data or perform unauthorized actions locally on your device. Since the attack is local, physical or app-level access is required.

Compliance Impact

The vulnerability involves improper export of Android application components, which could allow unauthorized local access to sensitive data. This may impact compliance with GDPR (data protection) and HIPAA (health information privacy) by increasing the risk of data breaches or unauthorized disclosures.

Mitigation Strategies

Immediately update textPlus to the latest version beyond 8.3.5 if available. If no update exists, uninstall the app until a patch is released. Monitor vendor advisories for fixes. Since the exploit is local and requires app interaction, removing the app reduces attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart