CVE-2026-85085 - Canva Android App WebView Cross-Origin Resource Access Vulnerability
CVE ID :CVE-2026-85085
Published : Sept. 4, 2026, 6 a.m. | 1 hour, 3 minutes ago
Description :The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 4, 2026, 6 a.m. | 1 hour, 3 minutes ago
Description :The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...