PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18907 TECNO Mobile CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.950Z and has not been modified since then. The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions. Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.

Vendor
TECNO Mobile
Product
Hi Browser
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-06
Advisory published
2026-08-05
Advisory updated
2026-08-06

Who should care

Organizations and individuals using com.talpa.hibrowser 2.23.1.1 on Android devices should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes verifying the presence of the vulnerable application within their inventory, reviewing application permissions, and ensuring that file downloads are properly validated and sanitized.

Technical summary

The CVE-2026-18907 vulnerability is a Path Traversal issue in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android. This vulnerability allows attackers to write arbitrary files via directory traversal sequences in filenames. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity rating. The vulnerability is caused by insufficient validation of filenames, allowing attackers to bypass intended access restrictions.

Defensive priority

Organizations should prioritize verifying the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within their inventory, reviewing the application's permissions, and ensuring that any file downloads are properly validated and sanitized.

Recommended defensive actions

  • Verify the presence of com.talpa.hibrowser 2.23.1.1 on Android devices within your inventory
  • Review the application's permissions and ensure that any file downloads are properly validated and sanitized
  • Implement compensating controls, such as monitoring for suspicious file writes or access to sensitive directories

Evidence notes

The CVE-2026-18907 record indicates a Path Traversal vulnerability in the Download File Feature of com.talpa.hibrowser 2.23.1.1 on Android, allowing for arbitrary file writes via directory traversal sequences in filenames. The CVSS score is 7.5, with a HIGH severity rating. The CVE was published on 2026-08-05T02:16:37.950Z and last modified on 2026-08-06T15:16:45.097Z. The NVD entry is currently Received.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.950Z and has not been modified since then.