A vulnerability was identified in the Inbox Foundry ActiveInbox Chrome Extension up to version 7.10.24. The vulnerability involves hard-coded Google OAuth client secret credentials embedded within the file dist/service-worker.production-esm.js. This exposure allows remote attackers to potentially abuse the OAuth credentials. A public exploit is available and may already be in use. The vendor was notified prior to disclosure but has not yet remediated the issue. The vendor's bug bounty program is currently on hold due to a backlog of existing reports, suggesting a delayed response to the vulnerability. Users of the affected extension versions are at risk of credential compromise and unauthorized access to Google OAuth-protected resources.