Impact
The Canva Android App, prior to version 2.376.0, fails to restrict HTTP headers that are returned to a WebView running with elevated privileges. This deficiency allows an attacker who can control the WebView—such as by loading a malicious web page or through an app that embeds Canva's WebView component—to access the user’s session information. The result is the ability to hijack the user’s authenticated session and potentially perform authorized actions on the user’s behalf, compromising confidentiality and integrity of the user’s data.
Affected Systems
Canva Android App versions earlier than 2.376.0 are vulnerable. The issue affects every installed instance of the app on Android devices that permits a privileged WebView to load external content.
Risk and Exploitability
The CVSS score for this vulnerability is 8.8, indicating a high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is an external website or malicious app that can inject content into Canva’s privileged WebView. An attacker needs only to drive the user into a compromised WebView; the application’s lack of header filtering means the attacker can read session identifiers or other sensitive headers and use them to impersonate the user. Given the high score and the straightforward exploitation path, the risk to exposed user sessions is significant.
OpenCVE Enrichment