The implicit grant returns an access token directly upon authorization being granted. By removing the additional network request, it can make your system vulnerable via manipulation of redirect URLs. if you’re implementing an OAuth 2 server, you can address this by validating the provided redirect URLs, but you should be doing that regardless.
My advice is to just always use the auth code grant with the PKCE extension. TLDR of that extension:
1) client generates a “secret key” that it sends with the authorization request.
2) server associates that key with the authorization code it returns to the authorized client
3) client must present that key again in order to exchange the authorization code for the access token.
Prevents the authorization code from being intercepted and abused.