ZeroHour

CVE-2026-49315

mass

Denial-of-Service Flaw in Huawei Input Device Module

CVSS 3.1
7.1 high
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-49315 is a high-severity (7.1) denial-of-service flaw in the input device module of Huawei device software, scored AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H and classified under CWE-264 (permissions/privileges). Exploitation requires local access to the device, with no special privileges or user interaction needed per the CVSS vector; a local attacker, for example via a malicious app or process, can trigger the module's faulty handling of input and cause a crash. The scope-changed (S:C) vector indicates the availability impact can extend beyond the vulnerable component itself, potentially disrupting the host system, with no confidentiality or integrity impact. The affected Huawei products and version ranges were not specified in the available data; the advisory wording matches the style of Huawei PSIRT's mobile OS (EMUI/HarmonyOS) security updates, which would place a large installed base of Huawei phones and tablets potentially in scope. There are no known public exploits or proofs of concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Check Huawei's PSIRT advisory for CVE-2026-49315 to confirm the affected EMUI/HarmonyOS versions and apply the corresponding Huawei security update when published. Because the attack vector is local (no network exposure), there is no remote mitigation; until patched, limit installation of untrusted apps on affected devices. Given no known exploitation, routine patching cadence is adequate, but treat the S:C scope change as a potential full-device crash risk.

Affected
Huawei Input device module (device operating system component)
Estimated exposure
masspotentially tens of millions or more Huawei devices (core OS module; affected versions unknown) — The input device module is a standard component of Huawei's mobile operating system stack (per Huawei PSIRT advisory conventions for EMUI/HarmonyOS), which runs on a global installed base in the hundreds of millions of phones and tablets,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.

Weakness
CWE-264
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.