Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-12792

Опубликовано: 18 нояб. 2025
Источник: nvd
CVSS3: 3.2
EPSS Низкий

Описание

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

EPSS

Процентиль: 1%
0.0001
Низкий

3.2 Low

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 3.2
github
3 месяца назад

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

EPSS

Процентиль: 1%
0.0001
Низкий

3.2 Low

CVSS3

Дефекты

CWE-276