The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90860 exposes a critical session hijacking vulnerability in Canva's mobile application for HarmonyOS devices running versions prior to v1.15.1. The flaw stems from improper WebView configuration that fails to restrict HTTP headers returned to external origins operating within a privileged context. This means an attacker who gains control of the WebView component can intercept sensitive session tokens and authentication credentials, potentially compromising user accounts and accessing private creative content, design files, and personal information. Mobile users on HarmonyOS devices represent the affected population, particularly those running older Canva versions where this header-filtering mechanism was not implemented.
While this CVE currently has no direct MITRE ATT&CK technique mapping and shows zero matching Casky skills, the underlying attack pattern aligns with credential access and session hijacking methodologies. A Casky practitioner using Claude's extended reasoning would investigate this by mapping the vulnerability to techniques like T1187 (Forced Authentication), T1040 (Traffic Capture or Replay), and T1528 (Steal Application Access Token). Detection would focus on identifying WebView implementations lacking origin validation, monitoring for unauthorized header exposure in mobile application logs, and flagging instances where external JavaScript contexts access privileged session data. Security teams should prioritize patching to v1.15.1 or later and implement runtime application self-protection (RASP) controls to validate WebView trust boundaries.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90860. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation