Local Code Execution Vulnerability in Canva for Mac Desktop App

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Local Code Execution Vulnerability in Canva for Mac Desktop App

Post by Shane1145 »

The Canva for Mac desktop application, prior to version 1.117.1, has a critical vulnerability that allows local threat actors with unprivileged access to execute arbitrary code. This security flaw arises from the absence of Hardened Runtime in the Mac App Store distribution, enabling attackers to leverage the app's TCC (Transparency, Consent, and Control) permissions. Users are advised to update to the latest version to mitigate this risk.

https://securityvulnerability.io/vulner ... 2025-12792
Post Reply