CVE-2025-12792 Details
Description
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
A vulnerability exists in the Canva for Mac desktop application distributed through the Mac App Store, prior to version 1.117.1. This version was released without the Hardened Runtime, allowing a local threat actor with unprivileged access to execute arbitrary code that could inherit the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Users are advised to upgrade to the latest version of the Canva application via the Mac App Store.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 18, 2025CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://trust.canva.com/?tcuUid=1e77a34b-f586-450b-b30d-b6e17d15b443 | Bugcrowd Inc. | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | Bugcrowd Inc. |
Affected Products
| Product | Versions |
|---|---|
| Canva | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Bugcrowd Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | Bugcrowd Inc. |
Volerion