CVE-2024-42218: 1password

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

Affected products

  • 1password 1password: from 8.0, before 8.10.38 (fixed in 8.10.38)

Published 2024-08-06. Last modified 2026-06-17.