ZeroHour

CVE-2026-49314

mass

Out-of-Bounds Write in Huawei Rendering and Composition Module

CVSS 3.1
7.3 high
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-49314 is an out-of-bounds write flaw in the rendering and composition module of Huawei software, assigned by Huawei's PSIRT (the listed CWE-125 nominally denotes an out-of-bounds read, but the advisory description describes a write). Per the CVSS vector, the attack vector is local: an attacker who can already run code on a device can trigger the flaw without needing privileges or user interaction, and successful exploitation may affect availability, most plausibly by crashing or hanging the graphics/rendering service, while the vector also scores a high-confidentiality component. The affected product line and version range are not stated in the available data; Huawei advisories worded this way typically cover the HarmonyOS/EMUI mobile OS graphics stack, but this should be confirmed against the Huawei PSIRT advisory. There is no public proof-of-concept, the flaw is not in CISA KEV, and no in-the-wild exploitation is known. Because the flaw sits in a core OS graphics component on a very large device fleet, the main control is prompt patch uptake once Huawei publishes patched builds.

What to do: Monitor the Huawei PSIRT advisory for CVE-2026-49314 for the exact affected HarmonyOS/EMUI versions and install the patched system/firmware build as soon as it is published (via device software update). Until patched, limit exposure to untrusted local applications on affected Huawei devices, since exploitation requires local code execution. No network-level mitigation applies given the local attack vector, and no PoC or in-the-wild exploitation is currently known.

Affected
Huawei Rendering and composition module (Huawei mobile OS graphics stack; likely HarmonyOS/EMUI per Huawei PSIRT advisory style
Estimated exposure
masspotentially hundreds of millions of Huawei devices (affected version range unspecified) — The module is part of the OS-bundled graphics stack and Huawei's HarmonyOS/EMUI ecosystems span hundreds of millions of devices, so the plausible ceiling is Huawei's overall install base, though without the affected version list the true…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.