
GitHub.dev passes full OAuth access to all user repositories upon one click. A malicious Jupyter Notebook triggers a webview to install a rogue extension and exfiltrate the token. The token grants read and write access to private repositories. Microsoft confirms the flaw and is working on a fix. The vulnerability affects only GitHub.dev, not VS Code Desktop.
Tap to vote and see what everyone thinks.
Ammar Askar Leaks VS Code Exploit After Microsoft Dispute
Summary by ByteBrief