A significant security flaw, identified as CVE-2024-42219, has been discovered in 1Password 8 for Mac. This vulnerability permits unauthorized access to vault items by circumventing the app’s built-in platform security features.
The issue was responsibly reported by Robinhood’s Red Team after they conducted an independent security review of 1Password for Mac.
Details of CVE-2024-42219
This flaw compromises the inter-process communication (IPC) safeguards in 1Password for Mac. Specifically, a locally running malicious process can exploit this weakness to bypass IPC protections.
This vulnerability allows attackers to hijack or impersonate trusted 1Password components, such as the browser extension or Command Line Interface (CLI), to gain unauthorized access.
All versions of 1Password 8 for Mac prior to version 8.10.36 (released in July 2024) are vulnerable. Users of these versions risk having their vault items stolen by malicious software.
To mitigate this issue, it is crucial for users to upgrade to the latest version, 1Password 8.10.36 for Mac, which includes patches to rectify the security flaw.
Exploiting this vulnerability requires the attacker to deploy malicious software on the target machine specifically designed to exploit 1Password for Mac. The exploit works by taking advantage of missing macOS-specific inter-process checks to hijack or impersonate a legitimate 1Password integration.
This could lead to the theft of vault contents and sensitive credentials, including the account unlock key and “SRP-𝑥” used during 1Password sign-in.
1Password relies on macOS’s native XPC interface for inter-process communication, which includes extra security measures through the hardened runtime. This runtime ensures that processes have tamper-resistance, preventing certain types of local attacks.
The identified flaw, caused by insufficient inter-process validation, has been addressed in the latest update. 1Password has thanked Robinhood’s Red Team for their responsible disclosure, which has allowed the company to enhance security measures for its users.
The company has confirmed that, to date, no reports have been made of anyone exploiting or even discovering this vulnerability.



