AI Stories on SHORT INFO are generated & curated with AI
unverified 09 Jun, 15:12

VS Code one-click zero-day on github.dev stole GitHub OAuth tokens via rogue extension, Microsoft patched June 3

Developers who opened a booby-trapped Jupyter notebook on github.dev risked handing attackers every repo they can touch, private ones included. The one-click VS Code flaw stole GitHub OAuth tokens via a rogue extension. Microsoft $MSFT patched it June 3, per BleepingComputer.

A single click was enough to hand over the keys to a developer's entire GitHub account. Security researcher Ammar Askar published details of a VS Code vulnerability on June 2 that allowed attackers to steal GitHub OAuth tokens through github.dev, the browser-based version of the editor. The attack chain was simple: a victim opens a specially crafted Jupyter notebook on github.dev, hidden code simulates keystrokes, and a malicious extension installs silently. That extension then grabs the OAuth token, which carries read and write access to every repository the victim can reach, including private ones. Askar released the details publicly after losing confidence in Microsoft's $MSFT coordinated disclosure process, an unusual step that put pressure on the company to move quickly. Microsoft shipped a fix on June 3 that adds a confirmation prompt before certain file types open on github.dev and blocks the extension commands the exploit relied on. For development teams the immediate takeaway is to treat notebooks and repo links from unknown sources as untrusted input, and to review which extensions and tokens have access to organizational repositories. Reporting: BleepingComputer, SecurityWeek, The Hacker News.

#cyber
Published on
BlueskyThreadsFacebookX