MEDIUM🇵🇱 Wersja polska

CVE-2022-29868

CVSS 5.5v3.1pub. 2022-05-09upd. 2024-11-21

1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and derived values used for signing in to 1Password.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • 1password

    APP
    1Password
    7.2.4 – 7.9.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-42219HIGH7.8same product

1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-proces...

CVE-2020-18173HIGH7.8same product

A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code...

CVE-2024-42218MEDIUM4.7same product

1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-speci...

CVE-2022-32550MEDIUM4.8same product

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations u...

CVE-2021-41795MEDIUM6.5same product

The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to auth...