Posts tagged

Hi-Browser
← Back to all posts
HB

Two Dots and a Slash: CVE-2026-18907 — Path Traversal in TECNO Hi Browser Turns a Download Into an Arbitrary File Write

On August 5, 2026, TECNO Mobile’s Security Response Center published CVE-2026-18907, a path-traversal vulnerability in Hi Browser (com.talpa.hibrowser) version 2.23.1.1 — TECNO’s first-party HiOS browser (the com.talpa.* application family on its Android handsets). N…