CVE-2025-43976

The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:textnow:2ndline:24.17.1.0:*:*:*:*:android:*:*

History

07 Aug 2025, 18:12

Type Values Removed Values Added
References () https://github.com/actuator/com.enflick.android.tn2ndLine - () https://github.com/actuator/com.enflick.android.tn2ndLine - Exploit
References () https://github.com/actuator/com.enflick.android.tn2ndLine/blob/main/CVE-2025-43976 - () https://github.com/actuator/com.enflick.android.tn2ndLine/blob/main/CVE-2025-43976 - Third Party Advisory
References () https://play.google.com/store/apps/details?id=com.enflick.android.tn2ndLine - () https://play.google.com/store/apps/details?id=com.enflick.android.tn2ndLine - Product
CWE CWE-862
Summary
  • (es) La aplicación com.enflick.android.tn2ndLine hasta la versión 24.17.1.0 para Android permite que cualquier aplicación instalada (sin permisos) realice llamadas telefónicas sin interacción del usuario enviando una intención manipuladas a través del componente com.enflick.android.TextNow.activities.DialerActivity.
CPE cpe:2.3:a:textnow:2ndline:24.17.1.0:*:*:*:*:android:*:*
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 5.5
First Time Textnow
Textnow 2ndline

22 Jul 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

21 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 15:15

Updated : 2025-08-07 18:12


NVD link : CVE-2025-43976

Mitre link : CVE-2025-43976

CVE.ORG link : CVE-2025-43976


JSON object : View

Products Affected

textnow

  • 2ndline
CWE
CWE-862

Missing Authorization