Executive brief
Canva's Android app before version 2.376.0 failed to properly restrict HTTP headers in a privileged WebView component, allowing attackers with control of the WebView to intercept and access user session credentials. This could enable account takeover or unauthorized access to a user's Canva design projects and personal data.
Technical details
The Canva Android application contains a privilege escalation vulnerability in its WebView implementation where headers returned from external origins are not properly restricted. An attacker who gains control over the WebView (through compromised JavaScript execution or content injection) can access sensitive session headers, leading to session hijacking. The vulnerability affects all versions before 2.376.0 and requires WebView compromise but could result in full account compromise. Canva has patched this issue in version 2.376.0 and later.
Affected products
- Canva Canva Android App before 2.376.0
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: Fixed in version 2.376.0