OneLogin Protect
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
OneLogin Protect authenticator, a free, enterprise-ready MFA app, provides two-factor authentication for all your OneLogin SSO accounts and thousands of third-party apps and services. When you use multi-factor authentication, you automatically increase the security of your online accounts. Features • Alerts user with a push notification, user responds with just a tap (OneLogin accounts only). • Requires your Touch ID, Face ID, or PIN to accept push notification (OneLogin accounts only). • Works with third-party providers and accounts which you can add at any time. • Compatible with services using OATH security tokens (i.e. Google Authenticator). • Generates a unique 6-digit code every 30 seconds for each account (TOTP). • Generates verification codes without a data connection. • Adds a new account by scanning a QR code or by entering it manually. • Securely backup and restore your accounts to your own Google Drive Permissions • Camera access for scanning QR code when adding new accounts.
Data collected and shared
Source: App Store · App Privacy · 2 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: OneLogin Protect
Why are no CVEs listed for OneLogin Protect?
No CVE is currently referenced in NVD for OneLogin Protect (com.onelogin.OneloginOTPApp) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of OneLogin Protect?
The most recent version of OneLogin Protect (com.onelogin.OneloginOTPApp) tracked by Appaloosa Scout is 4.8.8, published by OneLogin, LLC.