Path Traversal Vulnerability in HiBrowser for Android by Talpa
CVE-2026-18907

Currently unrated

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-18907?

A severe path traversal vulnerability exists in the download file feature of HiBrowser version 2.23.1.1 for Android, which permits attackers to exploit directory traversal sequences in filenames. This flaw enables unauthorized file write operations, potentially compromising the integrity and security of the affected device. Users are strongly advised to update to the latest version to mitigate this risk.

Affected Version(s)

Hi Browser 2.23.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.