1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
Link | Tags |
---|---|
https://app-updates.agilebits.com | release notes |
https://support.1password.com/kb/202408a/ | vendor advisory |