在 macOS 平台上,Canva 的 Affinity 应用程序在 3.3.1 版本(2026 年 10 月发布)之前,在生成 Affinity 文档文件的 QuickLook 缩略图和预览时,未对图像尺寸与像素数据大小进行验证,从而导致堆越界读取漏洞。攻击者可以构造一个恶意的 Affinity 文档,当用户在 Finder 中查看或预览该文档时,可能导致渲染的缩略图或预览图像泄露相邻堆内存内容,或致使缩略图或预览扩展程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96396 | 4.9 MEDIUM | Affinity macOS < 3.3.1 整数溢出致堆缓冲区溢出 |
| CVE-2026-103220 | 4.5 MEDIUM | Affinity 3.3.1前版本图像解析越界读漏洞 |
| CVE-2026-101094 | 3.6 LOW | Affinity 3.3.1前堆缓冲区越界读取致内存泄露或崩溃 |
| CVE-2026-96395 | 3.6 LOW | macOS Affinity <3.3.1 堆越界读取漏洞 |
| CVE-2026-96393 | 3.6 LOW | Affinity 3.3.1前越界指针解引用致崩溃 |
| CVE-2026-101130 | 3.6 LOW | Affinity 3.3.1前堆缓冲区越读漏洞 |
No comments yet