Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub OAuth Tokens Vulnerable to One-Click Attack

GitHub OAuth Tokens Vulnerable to One-Click Attack

Posted on June 3, 2026 By CWS

Cybersecurity experts have identified a new vulnerability in Microsoft Visual Studio Code (VS Code) that allows attackers to steal GitHub OAuth tokens with a single click. This alarming discovery highlights significant security risks for GitHub users, enabling unauthorized access to both public and private repositories.

Exploiting GitHub.dev’s Functionality

Security researcher Ammar Askar revealed that GitHub users are at risk when using the GitHub.dev feature, a web-based code editor that operates within a browser sandbox. This feature facilitates code commits and pull requests, functioning through OAuth tokens that permit GitHub interaction.

Askar explained that these tokens, crucial for GitHub.dev operations, are not restricted to specific repositories. Consequently, this lack of scope enables them to access all repositories the user can, thus broadening the potential impact of a breach.

The Mechanism Behind the Attack

The vulnerability leverages malicious VS Code extensions to hijack the OAuth tokens. Attackers exploit the message-passing mechanism between the main VS Code window and webviews, which render elements like Markdown previews. By executing harmful JavaScript within an untrusted webview, attackers simulate keypresses to open the Command Palette and install extensions that can extract tokens.

The attack further manipulates VS Code’s local workspace extensions feature. By placing extensions directly into specific folders, attackers bypass any trust dialog, avoiding the publisher trust check, and seamlessly installing unauthorized extensions.

Response and Mitigations

Microsoft was informed of the issue on June 2, 2026, and acknowledged the vulnerability shortly after. Although a fix is underway, the situation underscores the importance of vigilant cybersecurity practices among developers and organizations.

Alexandru Dima, a software engineering manager at Microsoft, clarified that this vulnerability does not impact the desktop version of VS Code, limiting the scope of the threat to the web-based environment. Users are encouraged to remain cautious and monitor updates from Microsoft regarding this issue.

As the cybersecurity community continues to address this vulnerability, it serves as a reminder of the evolving nature of digital threats and the necessity for robust security measures.

The Hacker News Tags:Attack, Cybersecurity, GitHub, GitHub.dev, OAuth, Security, software development, token theft, VS Code, Vulnerability

Post navigation

Previous Post: Apache ActiveMQ Vulnerability Exposes Security Risks
Next Post: WordPress Plugin Vulnerabilities Threaten Websites

Related Posts

Critical Vulnerability in Cursor Allows Windows Code Execution Critical Vulnerability in Cursor Allows Windows Code Execution The Hacker News
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization The Hacker News
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot The Hacker News
HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass The Hacker News
How to Gain Control of AI Agents and Non-Human Identities How to Gain Control of AI Agents and Non-Human Identities The Hacker News
Linux Kernel Vulnerabilities Highlight Security Concerns Linux Kernel Vulnerabilities Highlight Security Concerns The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark