CVE-2026-96395
Received Received - Intake

Heap Out-of-Bounds Read in Affinity by Canva macOS App

Vulnerability report for CVE-2026-96395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: 61adb53e-e4b3-47f7-8a93-4717c9e77dc6

Description

The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
canva affinity 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds heap read in the Affinity by Canva app for macOS before version 3.3.1. It occurs when the app generates QuickLook thumbnails and previews of Affinity document files without proper bounds checking. A crafted document could cause the app to read and disclose adjacent heap memory contents, including memory addresses, in the rendered thumbnail or preview.

Detection Guidance

This vulnerability involves an out-of-bounds heap read in Affinity by Canva for macOS versions before 3.3.1. Detection requires checking the installed version of the app. Use the command 'mdls /Applications/Affinity\ by\ Canva.app' to inspect the app's metadata for version details. If the version is below 3.3.1, the system is vulnerable.

Impact Analysis

An attacker could exploit this to view sensitive memory contents, such as memory addresses, when you preview or open an Affinity document in Finder. This could potentially expose internal application data but does not allow code execution or direct system compromise.

Mitigation Strategies

Update Affinity by Canva for macOS to version 3.3.1 or later immediately. Disable QuickLook previews for Affinity documents by running 'defaults write com.apple.finder QLEnableTextPreview -bool false' in Terminal, then restart Finder. Avoid opening untrusted Affinity documents until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart