Impact
The vulnerability in the Text Message and Call App allows the DialerActivity component to be improperly exported, creating a weakness that lets local attackers invoke this Activity from outside the application. This exceeds the intended application boundary and can expose or manipulate private data or functionality, potentially leading to data leakage or unauthorized actions on the device. The weakness is classified as CWE‑926, which describes inadequate restriction of component interaction within an application.
Affected Systems
All installations of the TextPlus Text Message and Call App up to version 8.3.5 are affected. No additional version information is available, but any build equal to or older than 8.3.5 carries the flaw.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The exploit requires local execution and is publicly available, but not yet listed in the CISA KEV catalog and no EPSS score is available, suggesting that while an attacker can exploit it, the likelihood of widespread exploitation is presently low. The risk remains present until the component can be properly marked as non‑exported or the app is patched.
OpenCVE Enrichment