What is CVE-2026-18907?
This vulnerability is a path traversal issue in the file download feature of HiBrowser for Android version 2.23.1.1, allowing arbitrary file writes via directory traversal sequences in the filename. Immediate application update is recommended to mitigate the risk.
Azərbaycanca: Bu boşluq HiBrowser-in Android versiyasında (2.23.1.1) fayl yükləmə xüsusiyyətində path traversal zəifliyidir ki, bu da təcavüzkara direktoriya keçid ardıcıllıqları vasitəsilə ixtiyari fayl yazmağa imkan verir. Cihazın təhlükəsizliyi üçün dərhal tətbiqi yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of HiBrowser is affected by CVE-2026-18907?
HiBrowser for Android version 2.23.1.1 is affected by this path traversal vulnerability.
What measure is recommended to protect against CVE-2026-18907?
Immediate application update is recommended to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.