Mark RadarMARK RADAR
EN

Researcher Discloses VS Code Zero-Day, Questions Microsoft’s Vulnerability Reporting Process

1 reports · First detected 2026-06-05 · Last active 2026-06-05

GitHub.dev is the browser-based version of Visual Studio Code offered by Microsoft-owned GitHub, allowing users to edit and commit code directly. The OAuth token obtained at login is not restricted to a single repository; it can cover every public and private repository the user is authorized to access. A single token leak could therefore put corporate source code and the software supply chain at risk, underscoring the importance of trust between researchers and the Microsoft Security Response Center (MSRC).

Security researcher Ammar Askar published technical details and a proof of concept on June 2, 2026, notifying GitHub just one hour before publication. An attacker could trick a user into clicking a specially crafted link and steal a GitHub OAuth token with read and write access. Microsoft added a confirmation step on June 3 before merging a full fix, saying the service had been mitigated and users did not need to take action. It has not disclosed the number of victims or the value of any losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)