Junglewise Threat Intelligence

CVE-2026-49315: Huawei HarmonyOS input device module denial of service

CVE-2026-49315 · Severity: high · CVSS 7.1 · Published 2026-09-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A denial-of-service vulnerability exists in the input device module of Huawei's HarmonyOS operating system, which powers smartphones, tablets, and smart TVs. An attacker can exploit this flaw to crash or hang affected devices, disrupting user access and operations. The vulnerability affects multiple widely-deployed HarmonyOS and EMUI versions across Huawei consumer devices.

Technical details

CVE-2026-49315 is a denial-of-service vulnerability in the input device module of Huawei HarmonyOS and EMUI. The vulnerability allows an attacker to trigger an availability impact through the input device subsystem; the specific attack vector (whether local, network, or user interaction) is not detailed in the advisory. The flaw affects HarmonyOS versions 4.0.0 through 4.3.3, as well as EMUI versions 14.0.0 through 16.0.0. Huawei has released patches as part of their September 2026 security update. No evidence of active exploitation in the wild has been reported.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1, 4.3.3
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0, 16.0.0

Timeline

  • 2026-09-09: disclosed: Vulnerability published in NVD
  • 2026-09: patched: Security update released by Huawei in September 2026

References

Related threats