OnePay
com.onefinance.one
View on App Store ↗
History
Current version : 5.87.0
Requires iOS ≥ 16.4
Devices: iPhone · iPad · iPod touch
★ 4.9
No CVE referenced at NVD for OnePay on iOS. Absence of CVEs is not a guarantee of security.
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- -
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee : it can also mean nobody has audited or published findings.
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Context
Context
Description
Meet your money super app. Through OnePay, you can bank, send, pay, spend, and borrow — plus build credit and earn cash back and rewards. OnePay is a financial technology company, not a bank. Banking services provided by Coastal Community Bank or Lead Bank, Member FDIC. Cash back earned as OnePay Points, redeemable as a deposit into a OnePay deposit account/other available options pursuant to the OnePay Rewards Terms at onepay.com/rewards-terms. For terms/conditions relating to OnePay products, onepay.com/terms. For individual reward details see OnePay app. For certain reward offers utilizing OnePay Credit Cards &, and 3rd-party cards linked in the OnePay Wallet, purchases must be made using the physical card. ^Fee-Free Overdraft is available to OnePay deposit accounts that have received Direct Deposits totaling $500+ in the current or previous month. You must be 18 or older. When on, Savings Backup will be used before Fee-Free Overdraft. Overdraft balance is due right away. Eligible transactions are at the discretion of OnePay and may exclude certain transactions (e.g., bill pay, global transfers).
Data collected and shared
Source: App Store · App Privacy · 7 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: OnePay
Why are no CVEs listed for OnePay?
No CVE is currently referenced in NVD for OnePay (com.onefinance.one) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of OnePay?
The most recent version of OnePay (com.onefinance.one) tracked by Appaloosa Scout is 5.87.0, published by One Finance, Inc..