A vulnerability (CVE-2026-82808) was discovered in Inbox Foundry's ActiveInbox Chrome Extension version up to 7.10.24. The extension ships a hardcoded Google OAuth client secret within the file dist/service-worker.production-esm.js, exposing credentials to potential attackers. The attack can be executed remotely and a public exploit is already available. The vendor was notified in advance but has not yet released a fix, citing a backlog of existing bug bounty reports with the programme currently on hold. This hard-coded credential vulnerability could allow unauthorized access to OAuth-protected resources associated with users of the extension. The issue represents a supply chain risk for Chrome users relying on this Gmail productivity extension.