Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical GitHub Token Flaw Risks User Security

Critical GitHub Token Flaw Risks User Security

Posted on June 3, 2026 By CWS

A significant security flaw in Visual Studio Code’s webview implementation has been identified, allowing malicious actors to steal GitHub OAuth tokens. This vulnerability could provide unauthorized access to users’ private repositories, requiring only a single malicious link click by the victim.

Details of the Vulnerability

On June 2, 2026, security expert Ammar Askar publicly disclosed this vulnerability. Askar chose to fully disclose the issue due to prior unsatisfactory interactions with Microsoft’s Security Response Center. The flaw is particularly concerning given that GitHub’s lightweight VSCode editor, accessed via github.dev, automatically transfers a user’s OAuth token from github.com. This token grants comprehensive access to all repositories the user has permission to access.

VSCode Webview Security Model

VSCode’s webview model is designed to isolate untrusted content through sandboxed iframes. However, it uses a postMessage API that allows communication between the main editor and these webviews. A vulnerability arises when untrusted JavaScript can simulate keyboard input, crossing the intended security boundaries.

Exploit Methodology

Askar demonstrated a complete exploit chain, which involves using a malicious Jupyter Notebook file to execute arbitrary JavaScript within a webview iframe. The attack can then silently install a malicious extension, bypassing trust checks by exploiting github.dev’s workspace trust characteristics.

Once installed, the extension can access preloaded GitHub OAuth tokens, allowing the attacker to enumerate and potentially modify private repositories. The vulnerability is particularly severe because the stolen token is not restricted to a single repository, making it a lucrative target for attackers.

Mitigation and Response

Users are advised to clear site data for github.dev in their browsers and avoid clicking on suspicious github.dev links until a patch is released. Regular auditing of installed extensions on github.dev is also recommended.

The incident highlights the need for robust security measures and timely updates to protect user data and prevent unauthorized access.

Cyber Security News Tags:Cybersecurity, Exploit, GitHub, Microsoft, OAuth, Security, Tokens, Visual Studio Code, Vulnerability, WebView

Post navigation

Previous Post: Anthropic Expands AI Cybersecurity Reach to 150 Organizations
Next Post: Weedhack Malware Targets Minecraft Players via YouTube

Related Posts

How To Defend Against These Phishing Kit Attacks  How To Defend Against These Phishing Kit Attacks  Cyber Security News
Cisco ISE Flaws Allow Remote Code Execution Cisco ISE Flaws Allow Remote Code Execution Cyber Security News
Nippon Steel Solutions 0-Day Network Vulnerability Exposes Users’ Personal Information Nippon Steel Solutions 0-Day Network Vulnerability Exposes Users’ Personal Information Cyber Security News
Threat Actors Allegedly Listed Windows Zero-Day RCE Exploit For Sale on Dark Web Threat Actors Allegedly Listed Windows Zero-Day RCE Exploit For Sale on Dark Web Cyber Security News
Zero-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams Zero-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams Cyber Security News
LummaStealer Technical Details Uncovered Using ML-Based Detection Approach LummaStealer Technical Details Uncovered Using ML-Based Detection Approach Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark