Impact
The Canva Android App loads external origins inside a privileged WebView, a weakness classified as CWE‑940: Improper Access Control. An attacker who controls the loaded web page can communicate with the app using the authenticated user’s session, enabling the exfiltration of personal Canva data or the execution of unauthorized actions within the application. While the flaw does not permit arbitrary code execution, the ability to hijack the session leads to significant confidentiality and integrity risks.
Affected Systems
The vulnerability affects all builds of the Canva Android Application released before version 2.376.0. Users who have not upgraded to the patched release, regardless of device model, are exposed to the compromised WebView behavior.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity impact. No EPSS score is available, and the flaw is not listed in CISA KEV, suggesting that public exploitation has not yet been confirmed. The likely attack vector is inferred from the description: exploitation requires a malicious web page to be loaded within the Canva app, which could be achieved through phishing or social engineering, after which the attacker can hijack the user’s session.
OpenCVE Enrichment