1Password secrets inadvertently logged in iOS system files

Published:

About the issue

An issue related to 1Password 7.4.3 was discovered in iOS 13, and may have affected previous versions of 1Password dating back to iOS 8. An Auto Layout logging error could trigger sensitive information revealed in 1Password to be written to a device’s system logs. That information could include credit card CVVs and passwords.

The issue was reported to us on March 26, 2020, and version 7.4.7 was released early the next day which had Auto Layout logging turned off. On March 27, 2020, 7.5.BETA-1 was released, which also had Auto Layout logging turned off.

Who may be affected

Because the iOS Auto Layout code changes from one version of iOS to the next, we cannot pinpoint when this issue began. The logging has been observed in iOS 13 and iOS 12. It is not known if it occurred in iOS 11 and earlier.

To be among those potentially affected, one of the following conditions must apply:

  • You’ve intentionally created and sent a sysdiagnose file to Apple or others in the past.
  • An attacker has administrative access to a previously trusted computer and your unlocked iOS device.
  • An attacker has physical access to your device and knows its passcode.

Impact and exploitability

Affected users may have had some secrets written to the iOS system log database, which is temporarily stored on the device. There are two ways to access the system log file. Each require physical access to an unlocked device and knowledge of the issue.

A malicious actor with physical access to an unlocked iOS device could have generated the  sysdiagnose file and shared it with themselves through AirDrop, email, or other means.

It’s also possible to extract the log file using a trusted Mac or Windows PC. To establish trust with a previously unknown computer, the attacker must know the passcode of the device. After trust has been established between devices, a malicious actor could have used the appropriate command in the terminal application to collect all system logs from the iOS device and located the secrets.

What you should do

If you’re using 7.4.3 or earlier, update to 1Password 7.4.7 or later, which has Auto Layout logging turned off.

If you have reason to suspect someone gained full access to your device and knew about the issue prior to the installation of 1Password 7.4.7, you may wish to change your passwords.

Commentary

The logging is completed by iOS itself, not 1Password, and is purged often. We have not observed any logs older than five days. On a frequently used device, most logs are 2-3 days old.

These logs are not sent to developers, nor to Apple for analytics purposes. They are not included in device backups.

Thanks

Credit to Shaun Mirani, Security Analyst with Independent Security Evaluators (ISE), for discovering and reporting this issue.