Description
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic path traversal flaw in the download file feature of com.talpa.hibrowser version 2.23.1.1 on Android devices. By providing a filename that contains directory traversal sequences, an attacker can force the application to write data to arbitrary locations on the device’s file system. The resulting impact is the ability to overwrite existing files, potentially including system or application files, and to place malicious files where they can be executed. The vulnerability is identified as CWE‑23. Possible privilege escalation is inferred, but the CVE description does not make this explicit.

Affected Systems

The affected product is TECNO Mobile Hi Browser 2.23.1.1 for Android. Only this specific build is documented as vulnerable; other builds were not mentioned as impacted.

Risk and Exploitability

The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. The CVSS score of 7.5 classifies it as high severity. Despite the low exploit probability, an arbitrary file write condition carries a high inherent risk because it can lead to data integrity loss, unauthorized file creation, and potentially execution of malicious code. The attack vector likely needs an attacker to invoke the download file functionality, either through a crafted request or a local user interaction. Given the CVSS score of 7.5 and the low EPSS score, administrators should treat this as a high‑severity issue and prioritize remediation.

Generated by OpenCVE AI on August 6, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Hi Browser to the latest version that contains the path traversal fix (e.g., 2.23.2.0 or newer).
  • If a patch is not yet available, disable or limit the download file feature and reduce the application’s file write permissions to its own sandboxed directories.
  • Continuously monitor devices for unauthorized file modifications, focusing on critical system directories, and review logs for suspicious activity.

Generated by OpenCVE AI on August 6, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tecno Mobile
Tecno Mobile hi Browser
Vendors & Products Tecno Mobile
Tecno Mobile hi Browser

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Description Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Title PathTravelsal Vulnerability in com.talpa.hibrowser
Weaknesses CWE-23
References

Subscriptions

Tecno Mobile Hi Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: TECNOMobile

Published:

Updated: 2026-08-06T13:51:48.166Z

Reserved: 2026-08-05T01:25:36.338Z

Link: CVE-2026-18907

cve-icon Vulnrichment

Updated: 2026-08-06T13:50:43.709Z

cve-icon NVD

Status : Received

Published: 2026-08-05T02:16:37.950

Modified: 2026-08-06T15:16:45.097

Link: CVE-2026-18907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:45:07Z

Weaknesses
  • CWE-23

    Relative Path Traversal