SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Grammarly's Flawed Chrome Extension Exposed Users' Private Documents
Date    Thursday February 08 2018, @08:14AM
Author    martyb
Topic   
from the more-gooder-coding dept.
https://soylentnews.org/article.pl?sid=18/02/08/0133234

Fnord666 writes:

Grammarly has fixed a security bug in its Chrome extension that inadvertently allowed access to a user's account -- including their private documents and data.

Tavis Ormandy, a security researcher at Google's Project Zero who found the "high severity" vulnerability, said the browser extension exposed authentication tokens to all websites.

That means any website can access a user's documents, history, logs, and other data, the bug report said.

"I'm calling this a high severity bug, because it seems like a pretty severe violation of user expectations," said Ormandy, because "users would not expect that visiting a website gives it permission to access documents or data they've typed into other websites."

In proof-of-concept code, he explained how to trigger the bug in four lines of code.

More than 22 million users have installed the grammar-checking extension.

[...] In a statement, a spokesperson for Grammarly confirmed the bug is fixed.

"At this time, Grammarly has no evidence that any user information was compromised by this issue. We're continuing to monitor actively for any unusual activity," the spokesperson said.

Story at ZDNet


Original Submission

Links

  1. "Fnord666" - https://soylentnews.org/~Fnord666/
  2. "ZDNet" - http://www.zdnet.com/article/grammarly-flawed-chrome-extension-exposed-private-documents/
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=24732

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Grammarly's Flawed Chrome Extension Exposed Users' Private Documents on 2024-04-20 15:45:47