Signing back into the Community for the first time? You'll need to reset your password to access your account.  Find out more.

Forum Discussion

Former Member's avatar
Former Member
2 years ago

AutoSpill information

I am looking for 1Password's release about how it will be mitigating our exposure to the AutoSpill vulnerability.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser: Not Provided

  • 1p_jac's avatar
    1p_jac
    Icon for 1Password Team rank1Password Team

    Hi @CrustyOldSysAdmin

    At 1Password, protecting your most important data is our utmost priority. A fix for AutoSpill has been identified and is currently being worked on.

    This fix is designed to enhance our security measures. It's important to note that 1Password's autofill already requires explicit user action for operation. The update will bolster this security feature by ensuring that only the fields in Android's WebView are autofilled, preventing unintended credential entry into native app fields.

    It's important to understand that the AutoSpill issue can only be exploited under very rare and specific conditions - first, if there's a malformed or malicious app installed on the device, and second, if there is intentional interaction to fill in a questionable WebView within that app. Both conditions would need to be true to experience any vulnerability. Our update will mitigate these risks even further.

    We remain committed to continuously improving our security features to safeguard your digital information, and we value the trust you place in 1Password.