CVE-2018-6654: Grammarly

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site.

Affected products

Published 2018-02-06. Last modified 2026-06-17.