To my knowledge, 1Password (which is what I use) has never had one of these bugs. There is one flaw reported in the P0 bugtracker against 1Password, that another user on the same local machine running native code can trick the 1Password agent into believing that it's your browser extension
https://crbug.com/project-zero/888 . All the machines where I run 1Password are single-user machines, so local processes running as other users aren't within my threat model anyway. (And I think this is 95%+ of people's threat models too on the machines where they run 1Password, although I understand why 1Password attempted to defend against this risk.)
1Password wrote an extended post in response to that vulnerability talking about defenses and threat models https://discussions.agilebits.com/discussion/70301/backgroun... and I don't see evidence that the vulnerability ever recurred.
And it was not a threat that allowed one website to get passwords for another website. It's true that other password managers have had such vulnerabilities - multiple times - but that's a reason to comparison-shop the various password managers and pick a secure one, not to write off the product category entirely.