logo

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

ID: 98df154e-83d6-5e4e-aa28-d7ba1094f2eb

STIX ID: report--98df154e-83d6-5e4e-aa28-d7ba1094f2eb

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: [email protected] (The Hacker News)

...
...

Security researcher Ammar Askar disclosed a one-click attack against GitHub.dev/VS Code webviews that allows malicious webview JavaScript to simulate keypresses, open the Command Palette, and install an attacker-controlled extension (leveraging local workspace extensions to bypass trust prompts) to exfiltrate GitHub OAuth tokens; the tokens can be used to enumerate and access private repositories. Microsoft acknowledged the vulnerability and is working on a remediation; the issue does not affect VS Code Desktop.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.