← Back to search

CVE-2026-18907

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows arbitrary file write through directory traversal sequences in the filename, enabling potential data corruption or malicious code execution on affected Android devices.
Exploitability
Exploitation requires control over the filename input and knowledge of the target device's file structure; it is moderately difficult to exploit without these details.
Blast radius
If exploited, this could lead to significant data loss or unauthorized modifications on the user’s device, impacting privacy and system integrity.
Prioritized remediation
Update to a patched version of com.talpa.hibrowser if available, or uninstall the application entirely.
file-writedirectory-traversalandroid

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-23

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.