


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.p…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 20:00:38
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A vulnerability was identified in the Inbox Foundry ActiveInbox Chrome Extension up to version 7.10.24. The vulnerability involves hard-coded Google OAuth client secret credentials embedded within the file dist/service-worker.production-esm.js. This exposure allows remote attackers to potentially abuse the OAuth credentials. A public exploit is available and may already be in use. The vendor was notified prior to disclosure but has not yet remediated the issue. The vendor's bug bounty program is currently on hold due to a backlog of existing reports, suggesting a delayed response to the vulnerability. Users of the affected extension versions are at risk of credential compromise and unauthorized access to Google OAuth-protected resources.
Technical details
Mitigation steps:
Affected products:
Inbox Foundry ActiveInbox Extension 7.10.24
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82808
https://github.com/xryj920/chrome_extensions/blob/main/The%20Inbox%20Foundry%20Limited%20ActiveInbox%207.10.24%20ships%20a%20hardcoded%20Google%20OAuth%20client%20secret%20in%20the%20Chrome%20extension%20bundle
https://vuldb.com/cve/CVE-2026-82808
https://vuldb.com/submit/874121
https://vuldb.com/vuln/397227
https://vuldb.com/vuln/397227/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
