WebView Vulnerability in Canva Mobile App for HarmonyOS
CVE-2026-90860
7.1HIGH
What is CVE-2026-90860?
The Canva Mobile App for HarmonyOS prior to version 1.15.1 is susceptible to a vulnerability that allows external origins running in a privileged WebView to access unauthorized data. A malicious actor, having control over the WebView, can potentially retrieve sensitive session information from users, compromising their privacy and app integrity. It is crucial for users to update their applications to the latest version to mitigate this risk.
Affected Version(s)
Canva HarmonyOS 0 < 1.15.1
