CVE-2026-85094
massSensitive Header Leak in Canva Android App WebView Enables Session Theft
Canva's Android app before version 2.376.0 failed to restrict the HTTP headers that are exposed to an external origin running inside the app's privileged WebView (CWE-212, sensitive information not properly handled before transfer). A threat actor who gains control of that WebView, for example by getting untrusted web content loaded in it, can read headers that carry the user's session credentials. With access to those credentials, the attacker can hijack the user's active Canva session and access the account. All users of the Canva Android app on versions earlier than 2.376.0 are affected; the record does not indicate whether iOS or desktop builds are also impacted. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2%), and no exploitation in the wild is currently known.
What to do: Update the Canva Android app to version 2.376.0 or later via Google Play and verify the installed version in the app's settings. Because the flaw exposes session credentials, users who suspect exposure should sign out and sign back in (or rotate their session) after updating, and monitor their Canva account for unusual activity.
| Canva Android App | all versions before 2.376.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
- Weakness
- CWE-212
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.