Overview
What is CVE-2026-49794?
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Vulnerability intelligence
CVE-2026-49794 and is rated Medium severity with a CVSS score of 4.6. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.