CVE-2026-18907 PUBLISHED

PathTravelsal Vulnerability in com.talpa.hibrowser

Assigner: TECNOMobile
Reserved: 05.08.2026 Published: 05.08.2026 Updated: 05.08.2026

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Product Status

Vendor TECNO Mobile
Product Hi Browser
Versions Default: unaffected
  • Version 2.23.1.1 is affected

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-126 Path Traversal