AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18907

HIGH · CVSS 7.5 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Download File feature in the com.talpa.hibrowser version 2.23.1.1 on Android is vulnerable to a path traversal attack, enabling attackers to write arbitrary files by exploiting directory traversal sequences in the filename. This vulnerability poses a significant risk as it could lead to unauthorized file access or manipulation on affected devices. Android developers and security teams should prioritize addressing this issue to mitigate potential exploitation risks.

CVE
CVE-2026-18907
Severity
HIGH
CVSS
7.5
EPSS
0.59%
Android

Original NVD Description

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.