Vulnerability · NVD
CVE-2022-29868
MEDIUM 5.5
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and derived values used for signing in to 1Password.
Attack vector : Local
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.16%
exploit very unlikely
percentile 5.2%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| 1password |
1password macOS
|
macOS | ≥7.2.4 <7.9.3 | cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* |