Authorization Bypass in 1Password for Mac Safari Extension
CVE-2021-41795

6.5MEDIUM

Key Information:

Vendor

1password

Status
Vendor
CVE Published:
29 September 2021

What is CVE-2021-41795?

The Safari app extension included in 1Password for Mac versions 7.7.0 through 7.8.x prior to 7.8.7 exhibits a vulnerability that enables an authorization bypass. This could allow a malicious website to gain unauthorized access to specific items within the user's vault, including usernames, passwords tied to their domains, unassociated usernames and passwords, credit card information, and contact details. Although 1Password needs to be unlocked for this information to be accessed, no additional user action is required, posing a significant risk of sensitive data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.