ZeroHour

CVE-2026-85085

mass

Privileged WebView cross-origin flaw in Canva Android app exposes user session

CVSS 3.1
9.6 critical
EPSS
<1%p13
Published
()
Modified
AI analysis

Canva's Android app prior to version 2.376.0 loaded external origins into a privileged WebView (CWE-940, improper restriction of communication channels to intended endpoints), allowing web content from outside Canva's trusted endpoints to interact with the app as if it were first-party. An attacker who controls the page the user loads, for example via a malicious link, can communicate with Canva using the victim's active session, producing high confidentiality and integrity impact with low availability impact under the published CVSS 3.1 score of 9.6. Users running the Canva Android app below 2.376.0 are affected; the provided data does not indicate whether Canva on iOS or the web is impacted. Triggering the flaw requires user interaction, and no public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, with EPSS currently estimating only a 0.2% probability of exploitation within 30 days.

What to do: Update the Canva Android app to 2.376.0 or later via Google Play and use MDM or endpoint inventories to confirm managed devices are at or above that version. Until updated, users should avoid opening untrusted links or pages inside the Canva app, and defenders can watch for Canva advisories confirming the fix scope across other platforms.

Affected
Canva Android Appbefore 2.376.0
Estimated exposure
masstens of millions of users (Canva's Android app has 100M+ Google Play installs) — Canva is a mass-market design platform with a very widely installed Android app (100M+ Google Play installs and >100M reported monthly active users), so the plausibly affected Android user base is on the order of tens of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

Weakness
CWE-940
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.