0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

GitHub.dev vulnerability allows theft of OAuth tokens for all repositories (heise.de)

· 52d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Researcher Ammar Askar discovered a GitHub.dev vulnerability
  • Attack steals OAuth tokens via simulated keystrokes
  • Microsoft has implemented a fix

"A security researcher discovered a vulnerability in the web version of VS Code on GitHub.dev that allowed attackers to steal a user's OAuth token via a crafted link. The attack used embedded preview windows and simulated keystrokes to install a malicious extension. Microsoft has patched the flaw."

Discussion Matrix

0 segments

no comments yet.