CVE-2025-12792: Canva
Low severity, CVSS 3.2. EPSS: 0.1% chance of exploitation in the next 30 days.
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Affected products
- Canva Canva: before 1.117.1 (fixed in 1.117.1)
Published 2025-11-18. Last modified 2026-06-17.