Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2026-18907 Details
Description
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
A path traversal vulnerability has been identified in the file download feature of com.talpa.hibrowser version 2.23.1.1 for Android. This vulnerability allows arbitrary file writing by exploiting directory traversal sequences in the filename.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Partial
CISA-ADP
Assessed Aug 6, 2026Exploitation: NoneAutomatable: YesTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tecno.com/SRC/securityUpdates | TECNOMobile | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | TECNOMobile |
Affected Products
| Product | Versions |
|---|---|
| com.talpa.hibrowser | 2.23.1.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | TECNOMobile |
Volerion