Executive brief
The Canva mobile app for HarmonyOS versions before 1.15.1 failed to restrict HTTP headers returned to external origins within a privileged WebView component. An attacker with control of the WebView could exploit this to steal session credentials and hijack a user's account, gaining unauthorized access to their design files and account data.
Technical details
A header restriction bypass vulnerability in the Canva HarmonyOS app's WebView allows an attacker controlling the WebView to read sensitive response headers—including session tokens—from cross-origin requests. The vulnerability requires the attacker to control the WebView context, a precondition that could be met through other compromises. No authentication bypass is required once this control is established; the impact is full session compromise.
Affected products
- Canva Mobile App for HarmonyOS before 1.15.1
Timeline
- 2026-09-21: disclosed