logo

Critical GitHub Token Stealing Bug Exploits Web-Based Code Editors

ID: 17babe87-0ea1-57d8-bead-a62aba64aa57

STIX ID: report--17babe87-0ea1-57d8-bead-a62aba64aa57

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Ddos

...
...

Independent research disclosed a critical vulnerability in the github.dev web-based VSCode interface that allows malicious content in the webview to forge did-keydown events and simulate keyboard shortcuts to bypass publisher trust and install local extensions, enabling theft of OAuth tokens with full access to a user's repositories; this poses a significant supply-chain and credential-exfiltration risk to browser users of github.dev.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.