CVE-2022-29868

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
09/05/2022
Last modified:
18/05/2022

Description

1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and derived values used for signing in to 1Password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* 7.2.4 (including) 7.9.3 (excluding)


References to Advisories, Solutions, and Tools