Huawei: Eleven Vulnerabilities in Graphics, Permissions, and Other Modules Disclosed Together
Key findings • Eleven Huawei vulnerabilities disclosed on September 9, 2026, span graphics, input, and permission control modules. • High severity flaws include DoS in input device module (CV…

Key findings
- Eleven Huawei vulnerabilities disclosed on September 9, 2026, span graphics, input, and permission control modules.
- High severity flaws include DoS in input device module (CVE-2026-49315) and OOB write in rendering (CVE-2026-49314).
- Multiple permission control vulnerabilities (CVE-2026-49310, CVE-2026-49311) impact confidentiality and availability.
- Vulnerabilities range from Medium (CVSS 4.3) to High (CVSS 8.6), primarily affecting service availability.
- Huawei has released patches; users should consult advisories for specific product updates.
On September 9, 2026, Huawei disclosed a batch of eleven vulnerabilities affecting its products, with a tight disclosure window of only three minutes. These vulnerabilities span various modules, including graphics, input device, rendering, and app management, with severities ranging from Medium to High. The primary impact across these vulnerabilities is a potential loss of availability or confidentiality.
Several vulnerabilities are related to memory management and data handling. CVE-2026-81647 and CVE-2026-81646, both rated Medium, stem from out-of-bounds read vulnerabilities in the graphics module, potentially impacting availability. Similarly, CVE-2026-49314, a High severity vulnerability, involves an out-of-bounds write in the rendering and composition module, also affecting availability. Another High severity vulnerability, CVE-2026-49315, is a DoS vulnerability in the input device module.
A significant cluster of vulnerabilities relates to permission control. CVE-2026-49310, a High severity flaw with a CVSS score of 8.6, is a permission control vulnerability in the event notification module that could affect service confidentiality. Its companion, CVE-2026-49311 (Medium severity), also in the event notification module, impacts availability. Other permission control issues include CVE-2026-49313 (Medium) in the app lock module, CVE-2026-49312 (Medium) in the window module, CVE-2026-49309 (Medium) in the Settings module, and CVE-2026-41987 (Medium) in the app management module, all with potential impacts on confidentiality or availability.
Additionally, CVE-2026-81644, a Medium severity DoS vulnerability, affects the preview service module, impacting availability.
Huawei has addressed these vulnerabilities through software updates. Users are advised to consult Huawei's official security advisories for specific product versions and patch information. The simultaneous disclosure of these eleven vulnerabilities underscores the importance of timely patching and security updates for Huawei users to mitigate potential risks to service availability and data confidentiality.
This batch of vulnerabilities highlights Huawei's ongoing efforts to address security weaknesses across its diverse product ecosystem. Users should remain vigilant and apply updates as soon as they become available to protect against potential exploitation. The range of affected modules indicates a broad security review, and continued monitoring of Huawei's security bulletins is recommended.