PT-2021-23408 · Agilebits · 1Password For Mac

Megamind

·

Published

2021-09-29

·

Updated

2022-07-12

·

CVE-2021-41795

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 1Password for Mac versions 7.7.0 through 7.8.x before 7.8.7
Description The Safari app extension bundled with 1Password for Mac is vulnerable to authorization bypass. A malicious web page could read a subset of 1Password vault items, including usernames and passwords for vault items associated with its domain, usernames and passwords without a domain association, credit cards, and contact items, by targeting a vulnerable component of this extension. These items are accessible when 1Password is unlocked, and no further user interaction is required.
Recommendations For 1Password for Mac versions 7.7.0 through 7.8.x before 7.8.7, update to version 7.8.7 or later to resolve the issue. As a temporary workaround, consider disabling the Safari app extension until a patch is available. Restrict access to sensitive vault items to minimize the risk of exploitation. Avoid using the 1Password extension on untrusted web pages until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-41795

Affected Products

1Password For Mac