1Password urges Mac users to patch now to avoid having their data stolen
1Password flaw could leave vaults exposed
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
1Password, one of thebest password managersaround right now, has urged Mac users to download a patch for their credential storage after a bug was discovered that allows attackers to crack open vaults.
1Password allows users to create password vaults within the app to separate their credentials between work and personal life for example.
But this vulnerability, tracked asCVE-2024-42219with a CVSS of 7.0, could be exploited by attackers to steal entire vaults of passwords from macOS users running 1Password version 8.10.36.
Cracking the vault
The flaw was discovered by security teams from Robinhood, who decided to test the 1Password app for vulnerabilities. Specifically, the National Vulnerability Database describes the flaw as allowing “local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.”
In anadvisory, the company stated, “To exploit the issue, an attacker must run malicious software on a computer specifically targeting 1Password for Mac. An attacker is able to misuse missing macOS-specific inter-process validations to hijack or impersonate a trusted 1Password integration such as the 1Password browser extension or CLI.”
“This would permit the malicious software to exfiltrate vault items, as well as obtain derived values used to sign in to 1Password, specifically the account unlock key and “SRP-𝑥”.”
The only way to exploit this flaw, an attacker would have to trick the users into installing a custom made program on the target machine, but so far there is no evidence that this has been done in the wild.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
1Password states that around 150,000 businesses rely on 1Password to store important credentials, but it is unclear how many of these use macOS devices. Windows users are not affected by this vulnerability.
More from TechRadar Pro
Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.
New fanless cooling technology enhances energy efficiency for AI workloads by achieving a 90% reduction in cooling power consumption
Samsung plans record-breaking 400-layer NAND chip that could be key to breaking 200TB barrier for ultra large capacity AI hyperscaler SSDs
NYT Strands today — hints, answers and spangram for Sunday, November 10 (game #252)