Impact
This vulnerability is a classic path traversal flaw in the download file feature of com.talpa.hibrowser version 2.23.1.1 on Android devices. By providing a filename that contains directory traversal sequences, an attacker can force the application to write data to arbitrary locations on the device’s file system. The resulting impact is the ability to overwrite existing files, potentially including system or application files, and to place malicious files where they can be executed by. The vulnerability is identified as CWE‑23. Possible privilege escalation is inferred, but the CVE description does not make this explicit.
Affected Systems
The affected product is TECNO Mobile Hi Browser 2.23.1.1 for Android. Only this specific build is documented as vulnerable; other builds were not mentioned as impacted.
Risk and Exploitability
There is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. Despite that, an arbitrary file write condition carries a high inherent risk because it can lead to data integrity loss, unauthorized file creation, and potentially execution of malicious code. The attack vector likely needs an attacker to invoke the download file functionality, either through a crafted request or a local user interaction. Given the severity of the impact and the absence of mitigation in the current build, administrators should treat this as a high‑severity issue and prioritize remediation.
OpenCVE Enrichment