Description
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Published: 2026-08-03
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Text Message and Call App allows the DialerActivity component to be improperly exported, creating a weakness that lets local attackers invoke this Activity from outside the application. This exceeds the intended application boundary and can expose or manipulate private data or functionality, potentially leading to data leakage or unauthorized actions on the device. The weakness is classified as CWE‑926, which describes inadequate restriction of component interaction within an application.

Affected Systems

All installations of the TextPlus Text Message and Call App up to version 8.3.5 are affected. No additional version information is available, but any build equal to or older than 8.3.5 carries the flaw.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. The exploit requires local execution and is publicly available, but not yet listed in the CISA KEV catalog and no EPSS score is available, suggesting that while an attacker can exploit it, the likelihood of widespread exploitation is presently low. The risk remains present until the component can be properly marked as non‑exported or the app is patched.

Generated by OpenCVE AI on August 4, 2026 at 10:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of the TextPlus Text Message and Call App that removes the exported DialerActivity component.
  • If an update is not yet available, uninstall or disable the TextPlus app to prevent the exploitation of its exported components.
  • Use device management or Android policy tools to enforce that only components explicitly declared as exported are exposed, and audit the manifest for unintended exports.

Generated by OpenCVE AI on August 4, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Title textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
First Time appeared Textplus
Textplus text Message And Call App
Weaknesses CWE-926
CPEs cpe:2.3:a:textplus:text_message_and_call_app:*:*:*:*:*:*:*:*
Vendors & Products Textplus
Textplus text Message And Call App
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Textplus Text Message And Call App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T20:06:55.762Z

Reserved: 2026-08-03T07:04:48.070Z

Link: CVE-2026-18604

cve-icon Vulnrichment

Updated: 2026-08-03T20:06:51.072Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T17:16:35.353

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:08Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components