CVE detail
CVE-2025-12792 — CVE-2025-12792
Published 2025-11-18 · Modified 2026-06-17 · Source nvd
LOW
severity
CVSS-derived band
0.0011
EPSS probability
exploitation probability, 30d
2.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References