The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canva
Canva canva |
|
| CPEs | cpe:2.3:a:canva:canva:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Canva
Canva canva |
Tue, 18 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva. | |
| Weaknesses | CWE-276 | |
| CPEs | ccpe:2.3:a:canva:canva:*:*:*:*:*:macos:*:* | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Bugcrowd
Published: 2025-11-18T00:18:00.348Z
Updated: 2025-11-18T06:09:01.547Z
Reserved: 2025-11-06T07:17:33.346Z
Link: CVE-2025-12792
No data.
Status : Received
Published: 2025-11-18T01:15:44.287
Modified: 2025-11-18T01:15:44.287
Link: CVE-2025-12792
No data.