CVE-2026-18907: Tecno Mobile Hi Browser

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Affected products

Published 2026-08-05. Last modified 2026-09-09.