CVE-2025-12792

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Configurations

No configuration.

History

18 Nov 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 01:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-12792

Mitre link : CVE-2025-12792

CVE.ORG link : CVE-2025-12792


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions