CyberRota Analysis
AI-GeneratedThe Download File feature in the com.talpa.hibrowser version 2.23.1.1 on Android is vulnerable to a path traversal attack, enabling attackers to write arbitrary files by exploiting directory traversal sequences in the filename. This vulnerability poses a significant risk as it could lead to unauthorized file access or manipulation on affected devices. Android developers and security teams should prioritize addressing this issue to mitigate potential exploitation risks.
CVE
CVE-2026-18907
Severity
HIGH
CVSS
7.5
EPSS
0.59%
Android
Original NVD Description
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.