Process Validation Bypass Vulnerability in 1Password for Mac

Process Validation Bypass Vulnerability in 1Password for Mac

CVE-2022-29868 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and derived values used for signing in to 1Password.

Learn more about our Web Application Penetration Testing UK.