top of page
perceptive_background_267k.jpg

A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.p…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 20:00:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A vulnerability was identified in the Inbox Foundry ActiveInbox Chrome Extension up to version 7.10.24. The vulnerability involves hard-coded Google OAuth client secret credentials embedded within the file dist/service-worker.production-esm.js. This exposure allows remote attackers to potentially abuse the OAuth credentials. A public exploit is available and may already be in use. The vendor was notified prior to disclosure but has not yet remediated the issue. The vendor's bug bounty program is currently on hold due to a backlog of existing reports, suggesting a delayed response to the vulnerability. Users of the affected extension versions are at risk of credential compromise and unauthorized access to Google OAuth-protected resources.

Technical details

Mitigation steps:

Affected products:

Inbox Foundry ActiveInbox Extension 7.10.24
Google Chrome

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page