CVE-2026-85085
massPrivileged WebView cross-origin flaw in Canva Android app exposes user session
Canva's Android app prior to version 2.376.0 loaded external origins into a privileged WebView (CWE-940, improper restriction of communication channels to intended endpoints), allowing web content from outside Canva's trusted endpoints to interact with the app as if it were first-party. An attacker who controls the page the user loads, for example via a malicious link, can communicate with Canva using the victim's active session, producing high confidentiality and integrity impact with low availability impact under the published CVSS 3.1 score of 9.6. Users running the Canva Android app below 2.376.0 are affected; the provided data does not indicate whether Canva on iOS or the web is impacted. Triggering the flaw requires user interaction, and no public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, with EPSS currently estimating only a 0.2% probability of exploitation within 30 days.
What to do: Update the Canva Android app to 2.376.0 or later via Google Play and use MDM or endpoint inventories to confirm managed devices are at or above that version. Until updated, users should avoid opening untrusted links or pages inside the Canva app, and defenders can watch for Canva advisories confirming the fix scope across other platforms.
| Canva Android App | before 2.376.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
- Weakness
- CWE-940
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.