Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-763v-59w8-w7gp

Опубликовано: 18 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.2

Описание

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

EPSS

Процентиль: 1%
0.00012
Низкий

3.2 Low

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 3.2
nvd
3 месяца назад

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

EPSS

Процентиль: 1%
0.00012
Низкий

3.2 Low

CVSS3

Дефекты

CWE-276