External risk intelligence

Canva Android WebView Vulnerability Allows Session Communication

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-85085

The vulnerability exists within a mobile application's WebView, requiring a user to interact with a specific external page within the app. It is a client-side issue rather than a public-facing network service, edge gateway, or internet-accessible appliance.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in the Canva Android App that could allow an attacker to interact with the app using a user's active session. The issue involves how the app loads external content within its interface, potentially enabling unauthorized communication. The primary concern is to confirm if this specific Canva app version is in use and if any exposure has occurred.

  • External page loads within app allow communication.
  • Potential for user session misuse by attackers.
  • Confirm app usage and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage, which then loads a privileged WebView within the Canva Android App. By controlling the content of this loaded page, the attacker can communicate with the app, potentially using the user's active session to interact with Canva's features. This could lead to the disclosure of sensitive information or unauthorized actions being performed on behalf of the user.

  • User visits attacker-controlled web page.
  • Privileged WebView loads attacker content.
  • Sensitive information disclosure or unauthorized actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to interact with a user's Canva session by controlling a webpage the user visits within the app. This communication could potentially lead to unauthorized actions or access to information within the user's session.

  • User session data at risk.
  • User interaction with malicious page.
  • Unauthorized session actions or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Canva Android app, requiring immediate attention from teams managing mobile applications and their associated infrastructure. The first critical step is to inventory all instances of the affected application, confirm their exposure to external manipulation, and identify the accountable application owner to initiate a risk-based remediation plan.

  • Mobile application owners should manage this issue.
  • Verify app exposure and business criticality.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Canva Android App?

The Canva Android App is a mobile platform used for graphic design, photo editing, and collaborative visual content creation. It provides tools that allow users to manage design projects and assets directly from their mobile devices. The software relies on WebView components to render web-based content and facilitate seamless integration between the app's native interface and its online services.

What does CVE-2026-85085 mean for security?

This vulnerability is classified as CWE-940, which involves improper handling of security-sensitive requests in a component. In the context of CVE-2026-85085, it means the application fails to properly restrict how its internal WebView communicates with external content. Because the WebView is privileged, it can act on behalf of the user, essentially allowing an untrusted website to trick the app into performing actions using the user's authenticated session.

How does an attacker trigger this vulnerability?

An attacker triggers this by enticing a user to navigate to a malicious webpage while using the Canva Android App. The vulnerability requires the user to interact with this specific external content through the app's browser component. It is not triggered by simply having the app installed or by network-level traffic alone; it requires the active loading and rendering of the attacker's page within the privileged WebView environment.

Is my organization at risk from this vulnerability?

According to Halo Surface Signal, this is considered very unlikely to be an internet-facing threat in the traditional sense, as the issue is client-side rather than a public-facing network service or server appliance. However, organizations should still care if employees use the Canva app on managed devices for work-related tasks, as an attacker could theoretically target those users to gain unauthorized access to their mobile design sessions.

How do I respond to this Canva vulnerability?

To address this, identify all managed Android devices where the Canva app is installed. Check the version numbers to determine if they are older than 2.376.0. If vulnerable versions are found, prioritize updating the application to the latest version through official channels. Work with your mobile device management team to ensure that users are running patched software and encourage them to be cautious when clicking links within mobile applications.

References