The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-85085 represents a critical authorization bypass vulnerability in the Canva Android application prior to version 2.376.0. The flaw enables external origins to load within a privileged WebView context, creating a bridge between attacker-controlled content and authenticated user sessions. This affects millions of Canva mobile users whose devices remain unpatched, particularly those in creative and design sectors relying on the platform for professional work. An attacker can exploit this by hosting malicious content and tricking users into visiting it, after which the malicious page gains direct access to communicate with Canva's privileged context using the victim's authenticated session—potentially leading to unauthorized access to designs, account data, or credential theft.
While this CVE does not map to specific MITRE ATT&CK techniques in the initial advisory, Casky's security skills powered by Claude AI would detect the underlying attack patterns associated with execution and credential access techniques. Practitioners using Casky would observe findings related to improper input validation, insecure WebView configuration (similar to T1203 - Exploitation for Client Execution), and session hijacking indicators (correlating with T1187 - Forced Authentication). The platform's 754 mapped skills would flag anomalies in WebView bridge communications, external URL loading patterns in privileged contexts, and unexpected cross-origin data flows. Security teams reviewing Casky's extended reasoning analysis would see detailed breakdowns of how the vulnerability chain works, enabling them to prioritize patching, implement WebView security controls, and monitor for exploitation attempts in user activity logs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-85085. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation