CPE
The ActiveInbox Chrome extension up to version 7.10.24 contains hard-coded Google OAuth Client Secrets in its service worker, potentially enabling unauthorized API access and OAuth flow manipulation.