VSCode Bug Allows 1-Click GitHub Token Stealing
TL;DR. A critical vulnerability in Microsoft VSCode allows attackers to steal GitHub tokens with a single click, compromising private repositories. - The flaw exploits VSCode's webview security model in browser-based github.dev instances. - Stolen OAuth tokens grant full read/write access to all user repositories, not just the currently viewed one. - Microsoft has patched the issue after full disclosure by the security researcher.
- A 1-click exploit in VSCode enables GitHub token theft.
- The vulnerability affects browser-based VSCode instances on github.dev.
- Stolen tokens grant broad access to all user repositories.
- The bug bypasses VSCode's webview sandboxing mechanisms.
- Microsoft has released a patch to address this security flaw.
Sources
- 1-Click GitHub Token Stealing via a VSCode Bug — blog.ammaraskar.com
- bleepingcomputer.com — bleepingcomputer.com
- thehackernews.com — thehackernews.com