Visual Studio Code zero-day vulnerability allows attackers to steal GitHub tokens

bleepingcomputer.com

A Visual Studio Code zero-day vulnerability allows attackers to steal GitHub tokens with a single click. The exploit enables malicious extensions to steal GitHub OAuth tokens by exploiting VS Code's webview message-passing system, granting access to private repositories. Users can mitigate the risk by clearing browser cookies and site data for github.dev.


With a significance score of 2.3, this news ranks in the top 21% of today's 33325 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Visual Studio Code zero-day vulnerability allows attackers to steal GitHub tokens | News Minimalist