Out-of-Bounds Pointer Dereference in Affinity by Canva App
CVE-2026-96393

3.6LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-96393?

The Affinity by Canva app prior to version 3.3.1 fails to implement adequate bounds checking when handling Affinity document files. This oversight can be exploited by a malicious actor crafting a specially designed Affinity document, which, when opened in the application, may cause an unexpected application crash. Users should ensure they are using the latest version to mitigate this risk.

Affected Version(s)

affinity 0 < 3.3.1

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.