Executive brief
The Canva Android app (used by over 220 million monthly active users for creating visual content) allowed malicious external websites to be loaded within a privileged WebView component before version 2.376.0. An attacker controlling a website could intercept the user's Canva session and perform actions on the user's behalf, potentially accessing or modifying designs and personal data.
Technical details
The vulnerability is a WebView origin validation flaw in which the Canva Android app failed to properly restrict which external origins could be loaded within a privileged WebView context. An attacker who controls a malicious webpage can trick a user into visiting it, and the page gains the ability to communicate with Canva using the user's authenticated session token. This allows the attacker to perform arbitrary actions (create, modify, or delete designs, access user data) without requiring additional authentication. The flaw was patched in version 2.376.0 released on 2026-09-04.
Affected products
- Canva Canva Android App before 2.376.0
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: Version 2.376.0