One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
ID: 98df154e-83d6-5e4e-aa28-d7ba1094f2eb
STIX ID: report--98df154e-83d6-5e4e-aa28-d7ba1094f2eb
Feed Name: The Hacker News
Security researcher Ammar Askar disclosed a one-click attack against GitHub.dev/VS Code webviews that allows malicious webview JavaScript to simulate keypresses, open the Command Palette, and install an attacker-controlled extension (leveraging local workspace extensions to bypass trust prompts) to exfiltrate GitHub OAuth tokens; the tokens can be used to enumerate and access private repositories. Microsoft acknowledged the vulnerability and is working on a remediation; the issue does not affect VS Code Desktop.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
