Out-of-Bounds Heap Read Vulnerability in Affinity by Canva for macOS
CVE-2026-96394

2.9LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-96394?

The Affinity by Canva application for macOS versions prior to 3.3.1 contains a vulnerability related to inadequate validation of image dimensions when generating QuickLook thumbnails. This flaw allows an attacker to create a specially crafted Affinity document that may reveal adjacent memory content during thumbnail generation, potentially exposing sensitive information or leading to application crashes. Users are recommended to update to the latest version to mitigate this risk.

Affected Version(s)

affinity MacOS 0 < 3.3.1

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.