CVE-2026-85085

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-08 14:03


NVD link : CVE-2026-85085

Mitre link : CVE-2026-85085

CVE.ORG link : CVE-2026-85085


JSON object : View

Products Affected

No product.

CWE
CWE-940

Improper Verification of Source of a Communication Channel