CVE-2026-85094: High severity Canva Android App vulnerability
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Canva Android Appto a version that resolves this vulnerability.Fixed in 2.376.0
Event History
Frequently Asked Questions
Which app versions are affected?
Canva Android App versions before 2.376.0 are affected. Updating to version 2.376.0 or later addresses the described issue.
What would an attacker need to exploit this issue?
The attacker would need control of an external origin loaded in a privileged WebView. Exploitation also requires user interaction, as indicated by the UI:R attack vector.
What is the potential impact on an affected user?
An attacker controlling the WebView could access the user’s session. The provided severity vector indicates potential high impact to confidentiality, integrity, and availability.