Executive brief
Affinity by Canva is a design and content creation application used by millions of users worldwide. A vulnerability in document parsing allows an attacker to craft a malicious Affinity document that, when opened by a user, could execute arbitrary code on their system. This poses a direct risk to user data, system integrity, and could lead to complete system compromise.
Technical details
The vulnerability is a stack-based buffer overflow caused by inadequate bounds checking when parsing Affinity document files. The affected component is the document file parser. The attack vector is user interaction: a threat actor must craft a malicious Affinity document and trick a user into opening it. Upon opening a crafted document in Affinity before version 3.3.0, the overflow occurs and an attacker can achieve arbitrary code execution with the privileges of the user running the application. The vulnerability is patched in Affinity version 3.3.0 (September 2026 release).
Affected products
- Canva Affinity before 3.3.0
Timeline
- 2026-09-17: disclosed
- 2026-09: patched: version 3.3.0 released