Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub OAuth Tokens Vulnerable to One-Click Attack

GitHub OAuth Tokens Vulnerable to One-Click Attack

Posted on June 3, 2026 By CWS

Cybersecurity experts have identified a new vulnerability in Microsoft Visual Studio Code (VS Code) that allows attackers to steal GitHub OAuth tokens with a single click. This alarming discovery highlights significant security risks for GitHub users, enabling unauthorized access to both public and private repositories.

Exploiting GitHub.dev’s Functionality

Security researcher Ammar Askar revealed that GitHub users are at risk when using the GitHub.dev feature, a web-based code editor that operates within a browser sandbox. This feature facilitates code commits and pull requests, functioning through OAuth tokens that permit GitHub interaction.

Askar explained that these tokens, crucial for GitHub.dev operations, are not restricted to specific repositories. Consequently, this lack of scope enables them to access all repositories the user can, thus broadening the potential impact of a breach.

The Mechanism Behind the Attack

The vulnerability leverages malicious VS Code extensions to hijack the OAuth tokens. Attackers exploit the message-passing mechanism between the main VS Code window and webviews, which render elements like Markdown previews. By executing harmful JavaScript within an untrusted webview, attackers simulate keypresses to open the Command Palette and install extensions that can extract tokens.

The attack further manipulates VS Code’s local workspace extensions feature. By placing extensions directly into specific folders, attackers bypass any trust dialog, avoiding the publisher trust check, and seamlessly installing unauthorized extensions.

Response and Mitigations

Microsoft was informed of the issue on June 2, 2026, and acknowledged the vulnerability shortly after. Although a fix is underway, the situation underscores the importance of vigilant cybersecurity practices among developers and organizations.

Alexandru Dima, a software engineering manager at Microsoft, clarified that this vulnerability does not impact the desktop version of VS Code, limiting the scope of the threat to the web-based environment. Users are encouraged to remain cautious and monitor updates from Microsoft regarding this issue.

As the cybersecurity community continues to address this vulnerability, it serves as a reminder of the evolving nature of digital threats and the necessity for robust security measures.

The Hacker News Tags:Attack, Cybersecurity, GitHub, GitHub.dev, OAuth, Security, software development, token theft, VS Code, Vulnerability

Post navigation

Previous Post: Apache ActiveMQ Vulnerability Exposes Security Risks
Next Post: WordPress Plugin Vulnerabilities Threaten Websites

Related Posts

Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks The Hacker News
Severe Bugs in AI Code Editor Risk System Intrusion Severe Bugs in AI Code Editor Risk System Intrusion The Hacker News
AI Value in SOCs: What the Next Wave Must Offer AI Value in SOCs: What the Next Wave Must Offer The Hacker News
Russia-Linked Hackers Target Tajikistan Government with Weaponized Word Documents Russia-Linked Hackers Target Tajikistan Government with Weaponized Word Documents The Hacker News
Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised The Hacker News
Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark