CVE-2026-49315
massDenial-of-Service Flaw in Huawei Input Device Module
CVE-2026-49315 is a high-severity (7.1) denial-of-service flaw in the input device module of Huawei device software, scored AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H and classified under CWE-264 (permissions/privileges). Exploitation requires local access to the device, with no special privileges or user interaction needed per the CVSS vector; a local attacker, for example via a malicious app or process, can trigger the module's faulty handling of input and cause a crash. The scope-changed (S:C) vector indicates the availability impact can extend beyond the vulnerable component itself, potentially disrupting the host system, with no confidentiality or integrity impact. The affected Huawei products and version ranges were not specified in the available data; the advisory wording matches the style of Huawei PSIRT's mobile OS (EMUI/HarmonyOS) security updates, which would place a large installed base of Huawei phones and tablets potentially in scope. There are no known public exploits or proofs of concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Check Huawei's PSIRT advisory for CVE-2026-49315 to confirm the affected EMUI/HarmonyOS versions and apply the corresponding Huawei security update when published. Because the attack vector is local (no network exposure), there is no remote mitigation; until patched, limit installation of untrusted apps on affected devices. Given no known exploitation, routine patching cadence is adequate, but treat the S:C scope change as a potential full-device crash risk.
| Huawei Input device module (device operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
- Weakness
- CWE-264
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.