CVE-2026-18907

TECNO Mobile · Hi Browser

A path traversal vulnerability in the Hi Browser download feature allows unauthenticated attackers to perform arbitrary file writes via malicious directory traversal sequences in the filename.

Executive summary

A critical path traversal vulnerability in TECNO Mobile Hi Browser version 2.23.1.1 poses a significant risk of arbitrary file write, potentially leading to system compromise.

Vulnerability

The application fails to properly sanitize filename inputs during the download process, which permits path traversal sequences. This flaw allows an unauthenticated, remote attacker to write files to unintended locations on the Android file system.

Business impact

The ability to write arbitrary files to the device file system creates a high risk of unauthorized code execution or system instability. Given the CVSS score of 7.5, this high-severity vulnerability could lead to total loss of data integrity or service availability on affected mobile devices. Organizations relying on this browser for business operations face potential compromise of sensitive local data and device-level security controls.

Remediation

Immediate Action: Users should immediately stop using the vulnerable version of Hi Browser and check the official TECNO Mobile security portal for an available update.

Proactive Monitoring: Security teams should monitor device traffic for unusual download activity or attempts to access system directories via the browser application.

Compensating Controls: Deploy endpoint security solutions that restrict unauthorized write access to critical system directories on managed Android devices.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the severity of this path traversal flaw, it is imperative that administrators and end users prioritize the application of security patches as soon as they are released by the vendor. Until a patch is confirmed, consider restricting the use of the Hi Browser application on corporate-managed devices to prevent potential exploitation.

Sources