1password < 7.0 denial of service Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2019-01-15 | Type : dos | Platform : android
This exploit / vulnerability 1password < 7.0 denial of service is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...


The 1Password application < 7.0 for Android is affected by a Denial Of
Service vulnerability. By starting the activity
com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or
com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an
external application (since they are exported), it is possible to crash the
1Password instance.


To invoke the exported activity and crash the app, it is possible
to use Drozer:

run app.activity.start --component com.agilebits.onepassword

Affected Components


Disclosure timeline

2018-07-27 Contacting 1Password

2018-07-30 1Password acknowledges the vulnerability

2018-08-22 The vulnerability is fixed and made public

Valerio Brussani (@val_brux)