Researcher Discloses VS Code Zero-Day, Questions Microsoft’s Vulnerability Reporting Process
GitHub.dev is the browser-based version of Visual Studio Code offered by Microsoft-owned GitHub, allowing users to edit and commit code directly. The OAuth token obtained at login is not restricted to a single repository; it can cover every public and private repository the user is authorized to access. A single token leak could therefore put corporate source code and the software supply chain at risk, underscoring the importance of trust between researchers and the Microsoft Security Response Center (MSRC).
Security researcher Ammar Askar published technical details and a proof of concept on June 2, 2026, notifying GitHub just one hour before publication. An attacker could trick a user into clicking a specially crafted link and steal a GitHub OAuth token with read and write access. Microsoft added a confirmation step on June 3 before merging a full fix, saying the service had been mitigated and users did not need to take action. It has not disclosed the number of victims or the value of any losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.