← 1Password

2024 1Password — CVE-2024-42219 macOS XPC flaw, local vault exfiltration

2024 Unknown records affected Share on X

Data compromised

Potential: vault items; account unlock key; SRP-x (if malware present)

Technical writeup

Insufficient XPC validation in 1Password 8 for Mac (versions before 8.10.36). Local malware could bypass platform security to hijack browser extension/CLI and exfiltrate vault items, account unlock key, SRP-x. Robinhood Red Team disclosed; patched in 8.10.36. No evidence of in-the-wild exploitation.

Root cause

Insufficient XPC validation; local privilege escalation

References