1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/HamzaMhirsi/CVE_details_NVD
- https://github.com/theulis/NIST-1Password-Kandji-Public
- https://github.com/theulis/NIST-1Password-Public