GHSA-97f3-2864-45mwCriticalCVSS 9.6
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged...
🔗 CVE IDs covered (1)
📋 Description
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.