Skip to content
1Password · SecurityJan 23, 2026, 20:04 UTC

1Password Browser Extension Code Syntax Rendering Issue

MinorNot disclosedUpdated 20h ago
Jan 23, 20:04 UTCJan 23, 20:04 UTC
Duration
0m
Impact
Minor
Root cause
Not disclosed
1Password, 90 days
7 incidents
Affected
Not listed by the vendor.
Status page

Final update

# Incident Postmortem - 1Password Browser Extension Code Syntax Rendering Issue **Customer impact began \(stable rollout start\):** 2025-12-09 **Investigation Started:** 2025-12-17 **Incident Declared \(UTC\):** 2025-12-30 13:13 **Fixed Release First Available:** 2026-01-01 **Fixed Release Fully Available and Verified:** 2026-01-05 **Incident Marked Resolved \(UTC\):** 2026-01-05 02:15 **Service\(s\) Affected:** 1Password browser extension ## Summary The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks. The issue was reported in beta in early December, escalated after additional customer reports and a report from an external partner, and required releasing a stable update to remove the problematic dependency chain. This issue affected page rendering only and did not expose vault data or credentials. ## Impact on Customers Customers experienced broken code-block syntax highlighting on websites with `` HTML elements while using the 1Password browser extension version 8.11.22 across all major browsers. * **Code snippet ren

Timeline

  1. Postmortem · Jan 23, 20:05 UTC
    # Incident Postmortem - 1Password Browser Extension Code Syntax Rendering Issue **Customer impact began \(stable rollout start\):** 2025-12-09 **Investigation Started:** 2025-12-17 **Incident Declared \(UTC\):** 2025-12-30 13:13 **Fixed Release First Available:** 2026-01-01 **Fixed Release Fully Available and Verified:** 2026-01-05 **Incident Marked Resolved \(UTC\):** 2026-01-05 02:15 **Service\(s\) Affected:** 1Password browser extension ## Summary The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks. The issue was reported in beta in early December, escalated after additional customer reports and a report from an external partner, and required releasing a stable update to remove the problematic dependency chain. This issue affected page rendering only and did not expose vault data or credentials. ## Impact on Customers Customers experienced broken code-block syntax highlighting on websites with `` HTML elements while using the 1Password browser extension version 8.11.22 across all major browsers. * **Code snippet rendering issue:** Syntax highlighting for code blocks was broken on sites that display code snippet; impacted sites included developer documentation pages, technical forums, and blogs with code snippets. * **Browser scope:** Reported in Chromium-based browsers initially, and confirmed to affect all ma
  2. Resolved · Jan 23, 20:04 UTC
    The 1Password browser extension, which works by injecting code into web pages, inadvertently included code from PrismJS, a third party dependency, breaking syntax highlighting on some websites that display code blocks.

More from 1Password

Full history

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.