Out-of-Bounds Vulnerability in Affinity by Canva for macOS
CVE-2026-96395

3.6LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-96395?

The Affinity by Canva app for macOS versions prior to 3.3.1 is vulnerable due to insufficient bounds checking during the generation of QuickLook thumbnails and previews of Affinity document files. This flaw could allow a malicious user to create a specially crafted Affinity document that, when previewed, exposes adjacent heap memory content. This leakage could reveal sensitive memory addresses and data within the rendered thumbnails or previews, posing a potential security risk for users.

Affected Version(s)

affinity MacOS 0 < 3.3.1

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.