ZeroHour

CVE-2026-85094

mass

Sensitive Header Leak in Canva Android App WebView Enables Session Theft

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

Canva's Android app before version 2.376.0 failed to restrict the HTTP headers that are exposed to an external origin running inside the app's privileged WebView (CWE-212, sensitive information not properly handled before transfer). A threat actor who gains control of that WebView, for example by getting untrusted web content loaded in it, can read headers that carry the user's session credentials. With access to those credentials, the attacker can hijack the user's active Canva session and access the account. All users of the Canva Android app on versions earlier than 2.376.0 are affected; the record does not indicate whether iOS or desktop builds are also impacted. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2%), and no exploitation in the wild is currently known.

What to do: Update the Canva Android app to version 2.376.0 or later via Google Play and verify the installed version in the app's settings. Because the flaw exposes session credentials, users who suspect exposure should sign out and sign back in (or rotate their session) after updating, and monitor their Canva account for unusual activity.

Affected
Canva Android Appall versions before 2.376.0
Estimated exposure
masstens of millions of users (Canva's Android app has 100M+ Google Play installs) — Canva is one of the most-installed Android apps, with a publicly reported user base exceeding 100 million monthly active users, so the affected version range plausibly spans tens to hundreds of millions of Android users; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

Weakness
CWE-212
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.