CVE-2025-64735

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

History

19 Mar 2026, 12:21

Type Values Removed Values Added
First Time Canva
Canva affinity
CPE cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2312 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2312 - Exploit, Third Party Advisory
References () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2312 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2312 - Exploit, Third Party Advisory

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de lectura fuera de límites existe en la funcionalidad EMF de Canva Affinity. Al usar un archivo EMF especialmente diseñado, un atacante podría explotar esta vulnerabilidad para realizar una lectura fuera de límites, lo que podría llevar a la divulgación de información sensible.

17 Mar 2026, 21:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2312 -

17 Mar 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 19:15

Updated : 2026-03-19 12:21


NVD link : CVE-2025-64735

Mitre link : CVE-2025-64735

CVE.ORG link : CVE-2025-64735


JSON object : View

Products Affected

canva

  • affinity
CWE
CWE-125

Out-of-bounds Read