CVE-2025-12792: Canva

Low severity, CVSS 3.2. EPSS: 0.1% chance of exploitation in the next 30 days.

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

Affected products

  • Canva Canva: before 1.117.1 (fixed in 1.117.1)

Published 2025-11-18. Last modified 2026-06-17.