PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18907 TECNO Mobile CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.950Z and has not been modified since then. The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions. Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.

Vendor
TECNO Mobile
Product
Hi Browser
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-09-09
Advisory published
2026-08-05
Advisory updated
2026-09-09

Who should care

Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.

Technical summary

The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions.

Defensive priority

Organizations should prioritize verifying the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within their inventory, reviewing the application's permissions, and ensuring that any file downloads are properly validated and sanitized.

Recommended defensive actions

  • Verify the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within your inventory
  • Review the application's permissions and ensure that any file downloads are properly validated and sanitized
  • Implement compensating controls, such as monitoring for suspicious file writes or access to sensitive directories

Evidence notes

The CVE-2026-18907 record indicates a Path Traversal vulnerability in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android, allowing for arbitrary file writes via directory traversal sequences in filenames. The CVSS score is 7.5, with a HIGH severity rating. The CVE was published on 2026-08-05T02:16:37.950Z and last modified on 2026-08-06T15:16:45.097Z. The NVD entry is currently Received.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18907 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18907

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18907 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18907

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://security.tecno.com/SRC/securityUpdates

    907edf6c-bf03-423e-ab1a-8da27e1aa1ea

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.