CVE-2026-82808 | Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials

SecurityVulns

A vulnerability was found in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome and classified as critical. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials.

This vulnerability is documented as CVE-2026-82808. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was informed beforehand about the issue. The support explains, that “[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports.”VulDB Recent EntriesRead More