Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: A 2018 bug in Grammarly’s browser extension reportedly exposed authentication tokens to websites. Contemporary reports said those tokens could have enabled access to text saved in Grammarly Editor. Grammarly said the flaw did not expose text typed on other websites while the extension was being used. The company said it fixed the bug within hours of its discovery. This was a historical vulnerability, not evidence that Grammarly is currently compromised.

What happened in 2018?

Google Project Zero researcher Tavis Ormandy reported a security bug in Grammarly’s browser extension. CyberScoop reported that the extension could expose authentication tokens to all websites. Those tokens could potentially let a malicious site access some Grammarly account data, including documents saved in Grammarly Editor.

The available contemporary coverage does not independently establish that attackers actually accessed or misused users’ data. It describes a potential access path and Grammarly’s response to the report.

Did the bug expose everything users typed?

No. The broad wording of the original headline is misleading when treated as a literal description of confirmed impact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Text that could have been affected

Contemporary reporting attributed the potentially affected material to text saved in Grammarly Editor. That is different from every sentence a person typed anywhere while Grammarly was installed.

Text reports said was not affected

Grammarly told reporters that text typed on other websites through the browser extension was not affected by this bug. The Register also reported that the issue did not affect text entered while using Grammarly Keyboard or the Microsoft Office add-in. These limits come from Grammarly’s statement and contemporaneous reporting, not from an independent reconstruction of the original Project Zero disclosure.

What information could the extension bug expose?

The key technical detail reported at the time was exposure of authentication tokens. A token can act as proof that a browser session is already authenticated, so a website receiving one might be able to make requests as that user, depending on how the service accepted and protected the token.

In this incident, reports connected that possibility to Grammarly user data and specifically narrowed the potentially accessible content to documents saved in Grammarly Editor. The sources available for this account do not provide the original implementation details, a CVE identifier, or evidence of verified exploitation, so those details should not be inferred.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did Grammarly do?

Grammarly said it fixed the issue within hours after it was discovered. Grammarly spokesperson Michael Mager said: “Grammarly resolved a security bug reported by Google’s Project Zero security researcher, Tavis Ormandy, within hours of its discovery…”

That is the company’s reported remediation timeline. It indicates a rapid patch, but it does not prove that every user was unaffected or that no data was accessed before the fix.

How the 2018 incident differs from Grammarly’s current operation

Current Grammarly support guidance describes a product that needs access to text in an active Grammarly context in order to provide writing suggestions. Grammarly says it cannot access text unless a user is actively using a Grammarly product, such as the browser extension, or an AI feature considers additional content.

Controls Grammarly says are available

  • You can control where Grammarly operates, which changes how much content it processes.
  • You can deactivate an AI feature when you do not want it to consider additional content.
  • You can turn Grammarly off entirely.
  • Grammarly says sensitive text, including passwords and credit-card information, is ignored or excluded on a best-effort basis. “Best effort” is not an absolute guarantee.

These statements describe current product behavior and user controls. They do not retroactively change the scope of the 2018 vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does Grammarly read everything I write today?

Not simply because the software is installed. According to Grammarly’s current support explanations, processing occurs when you actively use a Grammarly product or when an enabled AI feature considers additional content. Where Grammarly is enabled therefore matters: a text field with the extension active is different from a field or site where Grammarly has been turned off.

Grammarly’s privacy FAQ also points users to its controls for choosing where the service operates. The company identifies an ongoing HackerOne bug-bounty program as a way for external researchers to report potential security issues. A bug-bounty program can improve reporting, but it does not prove that a product is vulnerability-free.

How to turn Grammarly off for a field or site

The exact labels can change between browser-extension versions, but the practical control is to disable Grammarly where you do not want it processing text.

  1. Open the Grammarly browser-extension control while focused on the text field or website.
  2. Use the site or field toggle to turn Grammarly off for that location, if the control is available.
  3. For a complete stop, disable the Grammarly extension in your browser’s extensions manager or turn Grammarly off through its settings.
  4. Re-enable it only on sites and fields where you want writing suggestions.

If a control is missing or named differently, use Grammarly’s current support documentation for your browser and extension version rather than assuming that an older 2018 instruction still applies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What readers should conclude

  • The 2018 issue was a real reported security bug in Grammarly’s browser extension.
  • Reports described authentication-token exposure and potential access to Grammarly data.
  • The potentially affected content was narrowed to text saved in Grammarly Editor, not everything typed everywhere.
  • Grammarly said text typed on other websites, Grammarly Keyboard, and the Microsoft Office add-in was not affected by this bug.
  • Grammarly said it patched the flaw within hours, but the available reporting does not prove whether any data was actually accessed.
  • Current privacy and disable controls are relevant to present-day use, not evidence that the old vulnerability never existed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.