VSCode Bug Allows 1-Click GitHub Token Stealing

TL;DR. A critical vulnerability in Microsoft VSCode allows attackers to steal GitHub tokens with a single click, compromising private repositories. - The flaw exploits VSCode's webview security model in browser-based github.dev instances. - Stolen OAuth tokens grant full read/write access to all user repositories, not just the currently viewed one. - Microsoft has patched the issue after full disclosure by the security researcher.

Sources

Back to QLANKR News