I read the 1Password advisory on the WebP issue. Two things that were important to realize:
and
So, if one of my family members uses a modified 1Password program, they could compromise me if I display something from their account. This could happen if they downloaded 1Password from unofficial site.
an attacker needs to share an account with a victim to perform the attack.
and
By default, 1Password apps don’t permit creating WebP images. However, if an attacker uses a maliciously modified client, they may be able to create WebP images regardless.
So, if one of my family members uses a modified 1Password program, they could compromise me if I display something from their account. This could happen if they downloaded 1Password from unofficial site.