CVE-2026-18907

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
05/08/2026
Last modified:
06/08/2026

Description

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

References to Advisories, Solutions, and Tools