1Password maintains a focused portfolio of password management and secrets-handling applications, including its core vault product, command-line interface, and browser integration, deployed across consumer and enterprise environments where credential security is paramount. Vulnerabilities affecting the vendor concentrate on input-handling and information-disclosure weakness classes—improper input validation, unsafe equivalence checks, and cleartext storage of sensitive data—that reflect the parsing and cryptographic-boundary demands of credential-management software and frequently acquire public exploit code. Defenders should prioritize this vendor's updates given the sensitivity of data the products protect; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1password over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13042MEDIUM The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivi | Oct 5, 2018 | 5.9 | 35 | NO | YES |
CVE-2024-42219HIGH 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient. | Aug 6, 2024 | 7.8 | 25 | NO | NO |
CVE-2020-18173HIGH A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. | Jul 26, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-10256CRITICAL An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random numb | Oct 27, 2020 | 9.8 | 24 | NO | NO |
CVE-2021-41795MEDIUM The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extensio | Sep 29, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-26905MEDIUM 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key. | Feb 8, 2021 | 6.5 | 21 | NO | NO |
CVE-2022-29868MEDIUM 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Passwo | May 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2021-36758MEDIUM 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Mali | Jul 16, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-42218MEDIUM 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms. | Aug 6, 2024 | 4.7 | 19 | NO | NO |
CVE-2022-32550MEDIUM An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circum | Jun 15, 2022 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1password.
Media articles that mention a CVE ID that affects a product developed by 1password — matched by CVE ID, not by vendor name.