CVE-2026-18907

Summary

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Affected Software

VendorProductVersion RangeStatus
TECNO MobileHi Browser2.23.1.1affected

Weaknesses

  • CWE-23: CWE-23 Relative path traversal

References