1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
Link | Tags |
---|---|
https://app-updates.agilebits.com | release notes |
https://support.1password.com/kb/202408/ | vendor advisory |