📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

1Password AgileBits Inc.

1Password 8.12.32-26

Latest tracked version 8.12.32-26. Release status, tracked CVEs, and automated cross-platform patching for 1Password.

Category: Password Managers

PlatformLatest versionCVEs trackedLast checked
Windows8.12.32-2692026-08-10

Known vulnerabilities (CVEs) in 1Password

Lavawall tracks 9 published CVEs affecting 1Password, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2024-422192024-08-06 21:16:04HIGH (8)1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.LOCAL
CVE-2024-422182024-08-06 21:16:03MEDIUM (5)1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.LOCAL
CVE-2022-325502022-06-15 19:15:12MEDIUM (5)An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.NETWORK
CVE-2022-298682022-05-09 19:15:08MEDIUM (6)1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and derived values used for signing in to 1Password.LOCAL
CVE-2021-417952021-09-29 21:15:08MEDIUM (7)The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that would normally be fillable by the user on that web page. These items are usernames and passwords for vault items associated with its domain, usernames and passwords without a domain association, credit cards, and contact items. (1Password must be unlocked for these items to be accessible, but no further user interaction is required.)NETWORK
CVE-2020-181732021-07-26 20:15:08HIGH (8)A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.LOCAL
CVE-2018-130422018-10-05 21:29:01MEDIUM (4)The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.NETWORK
CVE-2014-37532020-01-09 14:15:11MEDIUM (6)AgileBits 1Password through 1.0.9.340 allows security feature bypassLOCAL
CVE-2012-63692012-12-28 11:48:45MEDIUM (4)Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action.NETWORK

Why keeping 1Password patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every 1Password release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches 1Password

Lavawall® watches 1Password releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on 1Password, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of 1Password?
Lavawall tracks 1Password at version 8.12.32-26 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does 1Password have known security vulnerabilities (CVEs)?
Lavawall tracks 9 CVEs for 1Password and remediates them automatically as part of patching.
How do I patch 1Password automatically?
Deploy the Lavawall® agent and 1Password updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for 1Password through public information and proprietary statistical analysis, and can patch it automatically across your fleet.