Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical GitHub Token Flaw Risks User Security

Critical GitHub Token Flaw Risks User Security

Posted on June 3, 2026 By CWS

A significant security flaw in Visual Studio Code’s webview implementation has been identified, allowing malicious actors to steal GitHub OAuth tokens. This vulnerability could provide unauthorized access to users’ private repositories, requiring only a single malicious link click by the victim.

Details of the Vulnerability

On June 2, 2026, security expert Ammar Askar publicly disclosed this vulnerability. Askar chose to fully disclose the issue due to prior unsatisfactory interactions with Microsoft’s Security Response Center. The flaw is particularly concerning given that GitHub’s lightweight VSCode editor, accessed via github.dev, automatically transfers a user’s OAuth token from github.com. This token grants comprehensive access to all repositories the user has permission to access.

VSCode Webview Security Model

VSCode’s webview model is designed to isolate untrusted content through sandboxed iframes. However, it uses a postMessage API that allows communication between the main editor and these webviews. A vulnerability arises when untrusted JavaScript can simulate keyboard input, crossing the intended security boundaries.

Exploit Methodology

Askar demonstrated a complete exploit chain, which involves using a malicious Jupyter Notebook file to execute arbitrary JavaScript within a webview iframe. The attack can then silently install a malicious extension, bypassing trust checks by exploiting github.dev’s workspace trust characteristics.

Once installed, the extension can access preloaded GitHub OAuth tokens, allowing the attacker to enumerate and potentially modify private repositories. The vulnerability is particularly severe because the stolen token is not restricted to a single repository, making it a lucrative target for attackers.

Mitigation and Response

Users are advised to clear site data for github.dev in their browsers and avoid clicking on suspicious github.dev links until a patch is released. Regular auditing of installed extensions on github.dev is also recommended.

The incident highlights the need for robust security measures and timely updates to protect user data and prevent unauthorized access.

Cyber Security News Tags:Cybersecurity, Exploit, GitHub, Microsoft, OAuth, Security, Tokens, Visual Studio Code, Vulnerability, WebView

Post navigation

Previous Post: Anthropic Expands AI Cybersecurity Reach to 150 Organizations
Next Post: Weedhack Malware Targets Minecraft Players via YouTube

Related Posts

AI-Powered Crypto Scam Targets Phone Numbers to Find Victims AI-Powered Crypto Scam Targets Phone Numbers to Find Victims Cyber Security News
ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection Cyber Security News
APT Hackers Attacking Indian Government Using GOGITTER tool and GITSHELLPAD Malware APT Hackers Attacking Indian Government Using GOGITTER tool and GITSHELLPAD Malware Cyber Security News
New Ransomware Attack Mocking Elon Musk Supporters Using PowerShell to Deploy Payloads New Ransomware Attack Mocking Elon Musk Supporters Using PowerShell to Deploy Payloads Cyber Security News
Counterfeit Ledger Wallets in China Pose Crypto Security Threat Counterfeit Ledger Wallets in China Pose Crypto Security Threat Cyber Security News
New Semantic Chaining Jailbreak Attack Bypasses Grok 4 and Gemini Nano Security Filters New Semantic Chaining Jailbreak Attack Bypasses Grok 4 and Gemini Nano Security Filters Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark