CyberRota Analysis
AI-GeneratedThe Canva Android App prior to version 2.376.0 is vulnerable due to insufficient restrictions on headers returned to an external origin within a privileged WebView. This flaw allows a threat actor controlling the WebView to access a user's session, potentially leading to unauthorized access to sensitive information. Android app developers and organizations using this app should prioritize remediation to protect user data from exploitation.
CVE
CVE-2026-85094
Severity
HIGH
CVSS
8.8
EPSS
0.23%
Android
Original NVD Description
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.