Skip to content
1Password · SecurityJan 23, 2026, 20:04 UTC

1Password Browser Extension Code Syntax Rendering Issue

MinorNot disclosedUpdated 38h ago
Jan 23, 20:04 UTCJan 23, 20:04 UTC
Duration
0m
Impact
Minor
Root cause
Not disclosed
1Password, 90 days
7 incidents
Affected
Not listed by the vendor.
Status page

Final update

# Incident Postmortem - 1Password Browser Extension Code Syntax Rendering Issue **Customer impact began \(stable rollout start\):** 2025-12-09 **Investigation Started:** 2025-12-17 **Incident Declared \(UTC\):** 2025-12-30 13:13 **Fixed Release First Available:** 2026-01-01 **Fixed Release Fully Available and Verified:** 2026-01-05 **Incident Marked Resolved \(UTC\):** 2026-01-05 02:15 **Service\(s\) Affected:** 1Password browser extension ## Summary The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks. The issue was reported in beta in early December, escalated after additional customer reports and a report from an external partner, and required releasing a stable update to remove the problematic dependency chain. This issue affected page rendering only and did not expose vault data or credentials. ## Impact on Customers Customers experienced broken code-block syntax highlighting on websites with `` HTML elements while using the 1Password browser extension version 8.11.22 across all major browsers. * **Code snippet ren

Timeline

  1. Postmortem · Jan 23, 20:05 UTC
    # Incident Postmortem - 1Password Browser Extension Code Syntax Rendering Issue **Customer impact began \(stable rollout start\):** 2025-12-09 **Investigation Started:** 2025-12-17 **Incident Declared \(UTC\):** 2025-12-30 13:13 **Fixed Release First Available:** 2026-01-01 **Fixed Release Fully Available and Verified:** 2026-01-05 **Incident Marked Resolved \(UTC\):** 2026-01-05 02:15 **Service\(s\) Affected:** 1Password browser extension ## Summary The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks. The issue was reported in beta in early December, escalated after additional customer reports and a report from an external partner, and required releasing a stable update to remove the problematic dependency chain. This issue affected page rendering only and did not expose vault data or credentials. ## Impact on Customers Customers experienced broken code-block syntax highlighting on websites with `` HTML elements while using the 1Password browser extension version 8.11.22 across all major browsers. * **Code snippet rendering issue:** Syntax highlighting for code blocks was broken on sites that display code snippet; impacted sites included developer documentation pages, technical forums, and blogs with code snippets. * **Browser scope:** Reported in Chromium-based browsers initially, and confirmed to affect all ma
  2. Resolved · Jan 23, 20:04 UTC
    The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks.

More from 1Password

Full history

Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Outages by email

Saturday mornings: the week's major outages, new postmortems and disclosed breaches, only in weeks that had some.

Double opt-in. Unsubscribe any time.