Out-of-Bounds Pointer Dereference in Affinity by Canva App
CVE-2026-96393
3.6LOW
What is CVE-2026-96393?
The Affinity by Canva app prior to version 3.3.1 fails to implement adequate bounds checking when handling Affinity document files. This oversight can be exploited by a malicious actor crafting a specially designed Affinity document, which, when opened in the application, may cause an unexpected application crash. Users should ensure they are using the latest version to mitigate this risk.
Affected Version(s)
affinity 0 < 3.3.1
