1-Click GitHub Token Stealing via a VSCode Bug

A security researcher details a vulnerability in the browser-based version of VSCode that allows attackers to steal GitHub OAuth tokens. By exploiting webview sandboxing, an attacker can gain unauthorized access to a user's private repositories.
Why it matters
This highlights a critical supply chain and platform security risk for developers using cloud-based IDEs.
Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones .
Technical report focused on cybersecurity vulnerabilities without political or social bias.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in