CVE-2025-12792
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-11-18
Assigner: Bugcrowd Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| canva | canva | 1.117.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists because the Mac App Store version of the Canva for Mac desktop app before version 1.117.1 was built without the Hardened Runtime security feature. As a result, a local attacker with limited (unprivileged) access could execute arbitrary code that inherits the app's Transparency, Consent, and Control (TCC) permissions, potentially allowing unauthorized access to protected resources.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow a local attacker to run arbitrary code with the same TCC permissions as the Canva app. This means the attacker could access or control sensitive user data or system features that the app has permission to use, potentially leading to privacy breaches or unauthorized actions on the affected system.