CyberRota Analysis
AI-GeneratedThe Canva Mobile App for HarmonyOS versions prior to 1.15.1 is vulnerable due to insufficient restrictions on headers returned to an external origin within a privileged WebView. This flaw allows a threat actor controlling the WebView to potentially access sensitive user session information. Organizations using this app should prioritize updates to mitigate the risk of session hijacking and protect user data.
CVE
CVE-2026-90860
Severity
HIGH
CVSS
7.1
EPSS
0.30%
Original NVD Description
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.