Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical GitHub Token Flaw Risks User Security

Critical GitHub Token Flaw Risks User Security

Posted on June 3, 2026 By CWS

A significant security flaw in Visual Studio Code’s webview implementation has been identified, allowing malicious actors to steal GitHub OAuth tokens. This vulnerability could provide unauthorized access to users’ private repositories, requiring only a single malicious link click by the victim.

Details of the Vulnerability

On June 2, 2026, security expert Ammar Askar publicly disclosed this vulnerability. Askar chose to fully disclose the issue due to prior unsatisfactory interactions with Microsoft’s Security Response Center. The flaw is particularly concerning given that GitHub’s lightweight VSCode editor, accessed via github.dev, automatically transfers a user’s OAuth token from github.com. This token grants comprehensive access to all repositories the user has permission to access.

VSCode Webview Security Model

VSCode’s webview model is designed to isolate untrusted content through sandboxed iframes. However, it uses a postMessage API that allows communication between the main editor and these webviews. A vulnerability arises when untrusted JavaScript can simulate keyboard input, crossing the intended security boundaries.

Exploit Methodology

Askar demonstrated a complete exploit chain, which involves using a malicious Jupyter Notebook file to execute arbitrary JavaScript within a webview iframe. The attack can then silently install a malicious extension, bypassing trust checks by exploiting github.dev’s workspace trust characteristics.

Once installed, the extension can access preloaded GitHub OAuth tokens, allowing the attacker to enumerate and potentially modify private repositories. The vulnerability is particularly severe because the stolen token is not restricted to a single repository, making it a lucrative target for attackers.

Mitigation and Response

Users are advised to clear site data for github.dev in their browsers and avoid clicking on suspicious github.dev links until a patch is released. Regular auditing of installed extensions on github.dev is also recommended.

The incident highlights the need for robust security measures and timely updates to protect user data and prevent unauthorized access.

Cyber Security News Tags:Cybersecurity, Exploit, GitHub, Microsoft, OAuth, Security, Tokens, Visual Studio Code, Vulnerability, WebView

Post navigation

Previous Post: Anthropic Expands AI Cybersecurity Reach to 150 Organizations
Next Post: Weedhack Malware Targets Minecraft Players via YouTube

Related Posts

Windows 11 Update Bug Affects Samsung Devices Windows 11 Update Bug Affects Samsung Devices Cyber Security News
Docker Open Sources Production-Ready Hardened Images for Free Docker Open Sources Production-Ready Hardened Images for Free Cyber Security News
Hackers Exploit NinjaOne Software for Covert Attacks Hackers Exploit NinjaOne Software for Covert Attacks Cyber Security News
Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Cyber Security News
Threat Actors Weaponizing Windows Scheduled Tasks to Establish Persistence Without Requiring Extra Tools Threat Actors Weaponizing Windows Scheduled Tasks to Establish Persistence Without Requiring Extra Tools Cyber Security News
WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark