<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Hi Browser (2.23.1.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hi-browser-2.23.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 16:07:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hi-browser-2.23.1.1/feed.xml" rel="self" type="application/rss+xml"/><item><title>Path Traversal Vulnerability in TECNO Hi Browser</title><link>https://feed.craftedsignal.io/briefs/2026-08-tecno-hi-browser-traversal/</link><pubDate>Tue, 11 Aug 2026 16:07:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tecno-hi-browser-traversal/</guid><description>TECNO Hi Browser version 2.23.1.1 is vulnerable to path traversal via malicious Content-Disposition headers, allowing arbitrary file writes outside the intended download directory.</description><content:encoded><![CDATA[<p>TECNO Hi Browser version 2.23.1.1 contains a path traversal vulnerability (CVE-2026-18907) in its download management functionality. The application fails to sanitize the 'filename' parameter provided in the 'Content-Disposition' HTTP response header. When a user downloads a file from a malicious server, the browser joins the attacker-provided filename directly to the target download directory path. An attacker can use directory traversal sequences, such as '../', within the filename to escape the designated storage area and write files to arbitrary locations accessible by the browser's storage permissions. This behavior poses a significant risk as it allows for the potential overwriting of application data or other files on the device. The issue has been addressed by the vendor in updated versions of the browser.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to write files outside of the authorized download directory on the user's Android device. If targeted effectively, this could lead to the modification of sensitive files, application hijacking, or the placement of malicious payloads in locations that could be executed or processed by the system, depending on the browser's storage permissions and device environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update TECNO Hi Browser to the latest version immediately to patch CVE-2026-18907.</li>
<li>Implement network-level egress filtering to restrict browser access to untrusted or newly registered domains if the environment requires strict control over mobile device traffic.</li>
<li>Security teams should perform periodic audits of mobile application download handlers to ensure they use basename sanitization and canonical path verification to prevent path traversal.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>