<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:inbox_foundry:activeinbox:*:*:*:*:*:chrome:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ainbox_foundryactiveinboxchrome/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 17:58:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ainbox_foundryactiveinboxchrome/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ActiveInbox Extension Hard-coded Google OAuth Client Secret</title><link>https://feed.craftedsignal.io/briefs/2026-08-activeinbox-hardcoded-credentials/</link><pubDate>Mon, 31 Aug 2026 17:58:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-activeinbox-hardcoded-credentials/</guid><description>The ActiveInbox Chrome extension up to version 7.10.24 contains hard-coded Google OAuth Client Secrets in its service worker, potentially enabling unauthorized API access and OAuth flow manipulation.</description><content:encoded><![CDATA[<p>A vulnerability identified as CVE-2026-82808 affects the Inbox Foundry ActiveInbox extension for Chrome, versions 7.10.24 and earlier. The issue lies within the dist/service-worker.production-esm.js file, which contains a hard-coded Google OAuth Client Secret. This security oversight allows for the extraction of sensitive credentials used to identify the application during OAuth authentication flows.</p>
<p>Remote attackers can leverage this hard-coded secret to perform unauthorized API requests or interfere with OAuth authentication processes for users of the extension. The vulnerability has been publicly disclosed, and proof-of-concept exploitation material is available, increasing the risk of abuse. Although the vendor was notified, they have noted that their bug bounty program is currently on hold, leaving the exposure present in legacy versions until an update is applied.</p>
<h2 id="impact">Impact</h2>
<p>The exposure of the Google OAuth Client Secret permits attackers to masquerade as the legitimate ActiveInbox application during OAuth handshake processes. This can lead to unauthorized access to user data connected via the extension or potential API manipulation, impacting the confidentiality and integrity of the integration between the user's email client and the ActiveInbox service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit internal software supply chains for instances of the ActiveInbox Chrome extension, version 7.10.24 or older.</li>
<li>Implement browser-based security policies to restrict or monitor the installation of extensions that have known hard-coded credential vulnerabilities.</li>
<li>Require users to rotate credentials or re-authenticate through updated service versions once a patch is provided by Inbox Foundry to invalidate the compromised client secret.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>credential-exposure</category><category>chrome-extension</category><category>oauth</category><category>cve-2026-82808</category></item></channel></rss>