3 ms·
If they can figure it out, they're sitting on potentially a very valuable exploit.
by computerfriend 3y ago
If they can figure it out, they're sitting on potentially a very valuable exploit.
- jdminhbg 3y agoOne that's been patched already, though, as they say that in current versions of Chrome and Grammarly it doesn't crash.
- chatmasta 3y agoYes, I too would like to read more details about this. It's a great writeup from an engineer who got stuck debugging this. But I hope some experts in security or reverse-engineering can replicate it and take a closer look. There's definitely a more interesting story here, probably regarding the localhost bridge between Grammarly extension and desktop. (Grammarly has a bug bounty btw... and their chrome extension has quite a large surface area...) If OP is here: can you provide the raw .gif file? (And if you're feeling generous, maybe even a minimal ruby example that replicates that templating setup, although it sounds like that wasn't required to reproduce it in the end.) P.S. "For security reasons, we do not have Chrome crash reporting enabled" - maybe consider disabling Grammarly extension for the same reasons ;)
- saulpw 3y agoIt wasn't the Grammarly extension, it was the desktop app.
- chatmasta 3y agoI guess I just assumed the extension was installed too, and communicating with the desktop app. But now I see the post doesn't mention the extension. If it was triggered even without the presence of the extension then that's quite strange, and even more suspicious - is that gif triggering a call to a localhost endpoint? Is the grammarly desktop app interacting with browser elements without using the extension? (IIRC the grammarly app uses some accessibility privileges to inject into textareas across all apps) Grammarly is honestly insane, I can't believe corporations allow it to run on employee machines.
- nonethewiser 3y ago> Is the grammarly desktop app interacting with browser elements without using the extension? (IIRC the grammarly app uses some accessibility privileges to inject into textareas across all apps) It seems like that must be the case. If we have the details right about desktop app only (which seemed pretty clear).
- Sophira 3y agoI'd also be interesting in seeing the raw .gif file - as a hobbyist wannabe researcher myself, I'd love to investigate this.