CVE-2025-12792: Low severity Canva Canva for Mac vulnerability
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12792?
CVE-2025-12792 has a high severity level due to the potential for local threat actors to execute arbitrary code.
How do I fix CVE-2025-12792?
To fix CVE-2025-12792, update Canva for Mac to version 1.117.1 or later.
What permissions can be exploited in CVE-2025-12792?
CVE-2025-12792 allows arbitrary code execution that can inherit the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Who is affected by CVE-2025-12792?
CVE-2025-12792 affects users of the Canva for Mac desktop app prior to version 1.117.1.
Is CVE-2025-12792 a remote or local vulnerability?
CVE-2025-12792 is a local vulnerability that requires unprivileged access to exploit.