CVE-2025-66000: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66000?
CVE-2025-66000 is classified with a critical severity as it allows attackers to exploit an out-of-bounds read vulnerability.
How do I fix CVE-2025-66000?
To fix CVE-2025-66000, update your Canva Affinity software to the latest version provided by Canva that addresses the vulnerability.
What is the impact of CVE-2025-66000 on Canva Affinity?
CVE-2025-66000 can potentially lead to the disclosure of sensitive information through an out-of-bounds read.
How can attackers exploit CVE-2025-66000?
Attackers can exploit CVE-2025-66000 by using specially crafted EMF files to trigger the out-of-bounds read in Canva Affinity.
Is there a workaround for CVE-2025-66000?
Currently, there are no known workarounds for CVE-2025-66000 other than applying the recommended software update.