{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-82808/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:inbox_foundry:activeinbox:*:*:*:*:*:chrome:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82808"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ActiveInbox Extension (\u003c= 7.10.24)"],"_cs_severities":["high"],"_cs_tags":["credential-exposure","chrome-extension","oauth","cve-2026-82808"],"_cs_type":"advisory","_cs_vendors":["Inbox Foundry"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-82808 affects the Inbox Foundry ActiveInbox extension for Chrome, versions 7.10.24 and earlier. The issue lies within the dist/service-worker.production-esm.js file, which contains a hard-coded Google OAuth Client Secret. This security oversight allows for the extraction of sensitive credentials used to identify the application during OAuth authentication flows.\u003c/p\u003e\n\u003cp\u003eRemote attackers can leverage this hard-coded secret to perform unauthorized API requests or interfere with OAuth authentication processes for users of the extension. The vulnerability has been publicly disclosed, and proof-of-concept exploitation material is available, increasing the risk of abuse. Although the vendor was notified, they have noted that their bug bounty program is currently on hold, leaving the exposure present in legacy versions until an update is applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe exposure of the Google OAuth Client Secret permits attackers to masquerade as the legitimate ActiveInbox application during OAuth handshake processes. This can lead to unauthorized access to user data connected via the extension or potential API manipulation, impacting the confidentiality and integrity of the integration between the user's email client and the ActiveInbox service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit internal software supply chains for instances of the ActiveInbox Chrome extension, version 7.10.24 or older.\u003c/li\u003e\n\u003cli\u003eImplement browser-based security policies to restrict or monitor the installation of extensions that have known hard-coded credential vulnerabilities.\u003c/li\u003e\n\u003cli\u003eRequire users to rotate credentials or re-authenticate through updated service versions once a patch is provided by Inbox Foundry to invalidate the compromised client secret.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T17:58:47Z","date_published":"2026-08-31T17:58:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-activeinbox-hardcoded-credentials/","summary":"The ActiveInbox Chrome extension up to version 7.10.24 contains hard-coded Google OAuth Client Secrets in its service worker, potentially enabling unauthorized API access and OAuth flow manipulation.","title":"ActiveInbox Extension Hard-coded Google OAuth Client Secret","url":"https://feed.craftedsignal.io/briefs/2026-08-activeinbox-hardcoded-credentials/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-82808","version":"https://jsonfeed.org/version/1.1"}