VYPR

Canva Mobile App

by Canva

CVEs (1)

  • CVE-2026-90860HigSep 21, 2026
    risk 0.46cvss 7.1epss

    The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.