CVE-2024-42219
HIGHDescription
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
Is your site exposed to CVE-2024-42219?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| 1password | 1password |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-42219? +
How severe is CVE-2024-42219? +
What products are affected by CVE-2024-42219? +
How do I check if I'm vulnerable to CVE-2024-42219? +
Related Vulnerabilities
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- …
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration …
Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission …
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts …
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns …
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, …