Description
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic path traversal flaw in the download file feature of com.talpa.hibrowser version 2.23.1.1 on Android devices. By providing a filename that contains directory traversal sequences, an attacker can force the application to write data to arbitrary locations on the device’s file system. The resulting impact is the ability to overwrite existing files, potentially including system or application files, and to place malicious files where they can be executed by. The vulnerability is identified as CWE‑23. Possible privilege escalation is inferred, but the CVE description does not make this explicit.

Affected Systems

The affected product is TECNO Mobile Hi Browser 2.23.1.1 for Android. Only this specific build is documented as vulnerable; other builds were not mentioned as impacted.

Risk and Exploitability

There is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. Despite that, an arbitrary file write condition carries a high inherent risk because it can lead to data integrity loss, unauthorized file creation, and potentially execution of malicious code. The attack vector likely needs an attacker to invoke the download file functionality, either through a crafted request or a local user interaction. Given the severity of the impact and the absence of mitigation in the current build, administrators should treat this as a high‑severity issue and prioritize remediation.

Generated by OpenCVE AI on August 5, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Hi Browser to the latest version that contains the path traversal fix (e.g., 2.23.2.0 or newer).
  • If a patch is not yet available, disable or limit the download file feature and reduce the application’s file write permissions to its own sandboxed directories.
  • Continuously monitor devices for unauthorized file modifications, focusing on critical system directories, and review logs for suspicious activity.

Generated by OpenCVE AI on August 5, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Description Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Title PathTravelsal Vulnerability in com.talpa.hibrowser
Weaknesses CWE-23
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TECNOMobile

Published:

Updated: 2026-08-05T01:47:16.191Z

Reserved: 2026-08-05T01:25:36.338Z

Link: CVE-2026-18907

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T04:00:06Z

Weaknesses
  • CWE-23

    Relative Path Traversal