
CVE-2026-18907 (7.5): TECNO Hi Browser trusted a Content-Disposition filename as a path. Two ../ and a download writes anywhere under /sdcard/. The CGI-era bug, alive on a billion pockets. Fix = one getCanonicalPath() check. #Android #PathTraversal #TECNO https://www.hunt-benito.com/blog/two-dots-and-a-slash-cve-2026-18907-path-traversal-in-tecno-hi-browser-turns-a-download-into-an-arbitrary-file-write/ https://t.co/4YEukGcBAv
Post summary
The post reports a path‑traversal flaw in TECNO Hi Browser that enables arbitrary writes to /sdcard and offers a simple getCanonicalPath() patch; no real‑world exploitation or PoC evidence is mentioned.
