The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
https://trust.canva.com/?tcuUid=be2ebc32-7053-4885-bf71-68771aa4589a