PatchSiren cyber security CVE debrief
CVE-2026-18907 TECNO Mobile CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.950Z and has not been modified since then. The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions. Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.
- Vendor
- TECNO Mobile
- Product
- Hi Browser
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-06
Who should care
Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.
Technical summary
The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions.
Defensive priority
Organizations should prioritize verifying the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within their inventory, reviewing the application's permissions, and ensuring that any file downloads are properly validated and sanitized.
Recommended defensive actions
- Verify the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within your inventory
- Review the application's permissions and ensure that any file downloads are properly validated and sanitized
- Implement compensating controls, such as monitoring for suspicious file writes or access to sensitive directories
Evidence notes
The CVE-2026-18907 record indicates a Path Traversal vulnerability in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android, allowing for arbitrary file writes via directory traversal sequences in filenames. The CVSS score is 7.5, with a HIGH severity rating. The CVE was published on 2026-08-05T02:16:37.950Z and last modified on 2026-08-06T15:16:45.097Z. The NVD entry is currently Received.
Official resources
-
CVE-2026-18907 CVE record
CVE.org
-
CVE-2026-18907 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
907edf6c-bf03-423e-ab1a-8da27e1aa1ea
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.950Z and has not been modified since then.