CVE-2018-6654: Grammarly
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site.
Affected products
- Grammarly Grammarly: version 2018-02-02 only
Published 2018-02-06. Last modified 2026-06-17.