SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Apple Product Help
AAPL 271.29+0.6%Oct 30 3:59 PM EDT

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
Recommended by:
NAG1
From: Zen Dollar Round8/11/2024 9:14:50 PM
1 Recommendation   of 6556
 
Critical 1Password flaw patched

1Password has patched a critical flaw in their password manager.
1Password users on Mac need to update urgently: attackers could access vaults

Popular password manager 1Password has patched a high-severity vulnerability that allows attackers to target Mac users and access sensitive secrets. The issue, tracked as CVE-2024-42219, affects all 1Password [8] for Mac versions before version 8.10.36, released in July 2024. … The vulnerability allows attackers to use malicious software and exfiltrate vault items, which basically means stealing passwords, credit cards, and other sensitive information stored in 1Password. Attackers can also obtain an account unlock key and a special code for signing into the application.
CVE-2024-42219 for 1Password 8 for Mac

If you’re using an affected version of 1Password for Mac, update to the latest version. … An attacker is able to misuse missing macOS specific inter-process validations to hijack or impersonate a trusted 1Password integration such as the 1Password browser extension or CLI. This would permit the malicious software to exfiltrate vault items, as well as obtain derived values used to sign in to 1Password, specifically the account unlock key and “SRP-??”.
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext