Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-85085: Canva Android app could let malicious page hijack user session

CVE-2026-85085 · published 1 day ago
Summary

Versions of the Canva app for Android earlier than 2.376.0 display web pages in a component that has extra permissions. If a user opens a malicious page, the attacker can communicate with the app using the user’s logged‑in session and could view or manipulate the user’s designs. Install the update (2.376.0 or newer) or remove the app until it is patched.

What to do
  • Update canva canva to version 2.376.0 or later.
Affected software
VendorProductAffected versions
canva canva < 2.376.0
Original advisory text
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using...
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Severity
9.6 Critical
CVSS 3.1: 9.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-940Improper Verification of Source of a Communication Channel
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85085 · MITRE
Monitor software like this
Free during beta