The Mac App Store distribution of the Canva for Mac...
Vulnerability Description
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12792
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- p1tsi (Bugcrowd)
More from Canva
View All →Affected Vendor
Canva
View all reports →