Impact
The Canva Mobile App for HarmonyOS before version 1.15.1 allows a malicious external origin running in a privileged WebView to receive all HTTP response headers. Because the app does not filter or block these headers, a threat actor controlling the WebView may capture a user’s session cookie or other authentication tokens, enabling the attacker to hijack the user’s account and gain unauthorized access to personal data and design assets, a misuse of sensitive header information.
Affected Systems
Any device running the Canva mobile application on HarmonyOS with a version older than 1.15.1 is affected. The flaw applies to the default WebView component used by the app, which is privileged and can process headers returned from external origins. Users of newer releases (1.15.1 or later) are not impacted.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability can be exploited through a malicious WebView endpoint that an attacker can control, potentially by tricking users into opening a crafted URL or loading malicious content. The CVSS score of 7.1 indicates a high impact vulnerability. The EPSS metric is currently unavailable, and the flaw is not listed in the CISA KEV product catalog, suggesting no known active exploitation. Due to the privileged nature of the WebView, the attack path likely requires user interaction, but once executed it can lead to full session compromise.
OpenCVE Enrichment