CVE-2026-18604: Textplus Text Message And Call App

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

Affected products

  • Textplus Text Message And Call App: version 8.3.0 only; version 8.3.1 only; version 8.3.2 only; version 8.3.3 only; version 8.3.4 only; version 8.3.5 only

Published 2026-08-03. Last modified 2026-08-12.