Out-of-Bounds Vulnerability in Affinity by Canva for macOS
CVE-2026-96395
3.6LOW
What is CVE-2026-96395?
The Affinity by Canva app for macOS versions prior to 3.3.1 is vulnerable due to insufficient bounds checking during the generation of QuickLook thumbnails and previews of Affinity document files. This flaw could allow a malicious user to create a specially crafted Affinity document that, when previewed, exposes adjacent heap memory content. This leakage could reveal sensitive memory addresses and data within the rendered thumbnails or previews, posing a potential security risk for users.
Affected Version(s)
affinity MacOS 0 < 3.3.1
