A security vulnerability was identified in the Canva Android App prior to version 2.376.0. The flaw allowed external origins to be loaded within a privileged WebView component, bypassing intended security boundaries. An attacker who controls the content loaded by the user could communicate with Canva's backend using the victim's authenticated session. This effectively enables session hijacking or unauthorized actions performed on behalf of the user. The vulnerability poses significant risk to users who may be tricked into loading malicious content. It has been assigned CVE-2026-85085 and is documented in the NVD. The issue has been addressed in Canva Android App version 2.376.0 and later.