HB
Two Dots and a Slash: CVE-2026-18907 ā Path Traversal in TECNO Hi Browser Turns a Download Into an Arbitrary File Write
On August 5, 2026, TECNO Mobile’s Security Response Center published CVE-2026-18907, a path-traversal vulnerability in Hi Browser (com.talpa.hibrowser) version 2.23.1.1 ā TECNO’s first-party HiOS browser (the com.talpa.* application family on its Android handsets). Nā¦