CVE-2025-43976: Textnow 2ndline

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.

Affected products

  • Textnow 2ndline: version 24.17.1.0 only

Published 2025-07-21. Last modified 2026-06-17.