CVE-2026-18907 is a path traversal vulnerability in the download file feature of com.talpa.hibrowser version 2.23.1.1 on Android. The flaw arises from insufficient neutralization of directory traversal sequences in a user-controllable filename during file download handling. By supplying a crafted filename containing traversal elements, an attacker can cause the application to write a downloaded file outside the intended destination directory. This results in an arbitrary file write condition within locations writable by the application, with potential consequences depending on the targeted path and the app's effective storage permissions and sandbox access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-18907, a path traversal vulnerability in TECNO Hi Browser's download handling. It contains two executable Python files and a README. The exploit is not tied to a common offensive framework. Structure and purpose: - evil_server.py: attacker-controlled HTTP delivery server. It listens on a configurable host/port (default 0.0.0.0:8000) and responds to GET/HEAD/POST with a file download. The key malicious behavior is setting Content-Disposition: attachment; filename="../.../target" so a vulnerable client treats traversal sequences as part of the destination path. - naive_downloader.py: local demonstration client that reproduces the vulnerable pattern by parsing Content-Disposition and joining the supplied filename directly onto a download directory. It also includes a corrected implementation using basename reduction plus canonical-path containment checks, making the root cause and remediation explicit. - README.md: documents the CVE, usage, Android testing workflow, expected escaped paths, and remediation guidance. Main exploit capability: The repository demonstrates a remote file-write primitive via malicious HTTP response headers. A vulnerable browser or downloader that auto-processes attachment downloads and trusts the filename parameter can be induced to write attacker-controlled bytes outside the intended download directory. The exploit does not provide code execution by itself; it provides arbitrary path-controlled file placement within the permissions of the victim application. Operational flow: 1. Attacker runs evil_server.py. 2. Victim client requests the hosted URL. 3. Server returns a binary body plus a traversal filename in Content-Disposition. 4. Vulnerable client joins download_dir with the attacker-supplied filename, allowing ../ traversal. 5. File is written to an escaped path such as /tmp/pwned.txt or /sdcard/pwned.txt. Notable implementation details: - The traversal depth is configurable with --depth. - The landing filename is configurable with --target. - The server supports GET, HEAD, and POST to make triggering flexible. - The downloader explicitly contrasts vulnerable and fixed behavior in one run. Overall, this is a legitimate operational PoC for demonstrating and reproducing the vulnerability class and the specific CVE behavior, centered on malicious HTTP delivery and unsafe filename handling in download logic.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.