GitHub.dev vulnerability allows theft of OAuth tokens for all repositories (heise.de)
0xBASE INTEL BRIEF
- Researcher Ammar Askar discovered a GitHub.dev vulnerability
- Attack steals OAuth tokens via simulated keystrokes
- Microsoft has implemented a fix
"A security researcher discovered a vulnerability in the web version of VS Code on GitHub.dev that allowed attackers to steal a user's OAuth token via a crafted link. The attack used embedded preview windows and simulated keystrokes to install a malicious extension. Microsoft has patched the flaw."
no comments yet.