Local Code Execution Vulnerability in Canva for Mac Desktop App
CVE-2025-12792

3.2LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-12792?

The Canva for Mac desktop application, prior to version 1.117.1, has a critical vulnerability that allows local threat actors with unprivileged access to execute arbitrary code. This security flaw arises from the absence of Hardened Runtime in the Mac App Store distribution, enabling attackers to leverage the app's TCC (Transparency, Consent, and Control) permissions. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

Canva macOS 0 < 1.117.1

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

p1tsi (Bugcrowd)
.
CVE-2025-12792 : Local Code Execution Vulnerability in Canva for Mac Desktop App