CVE-2026-18907
7.5 HIGHPublished 2026-08-05 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw allows arbitrary file write through directory traversal sequences in the filename, enabling potential data corruption or malicious code execution on affected Android devices.
- Exploitability
- Exploitation requires control over the filename input and knowledge of the target device's file structure; it is moderately difficult to exploit without these details.
- Blast radius
- If exploited, this could lead to significant data loss or unauthorized modifications on the user’s device, impacting privacy and system integrity.
- Prioritized remediation
- Update to a patched version of com.talpa.hibrowser if available, or uninstall the application entirely.
file-writedirectory-traversalandroid
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-23
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.