WebView Vulnerability in Canva Android App
CVE-2026-85085
9.6CRITICAL
What is CVE-2026-85085?
The Canva Android app prior to version 2.376.0 contains a vulnerability that permits an external origin to be loaded within a privileged WebView. This can lead to a scenario where a malicious actor controlling the external page can exploit the user's session, facilitating unauthorized communication with Canva. Users are advised to update their application to the latest version to mitigate this risk.
Affected Version(s)
Canva Android 0
