Hacker News new | ask | show | jobs
by MartijnHols 442 days ago
The article mentions they inject a web component. I imagine a bad actor could add something to that. In this case at the very least the author could add a "I hacked your Grammarly extension" text just via CSS, but I'm sure you can go much further, even more so with other extensions (eg password managers).
1 comments

But you could also just add you own lookalike web component to you page that looks like the grammarly one. If people enter credentials there, it's user error.