VS Code Zero-Day Exposes GitHub Tokens Via Single Click
A critical zero-day vulnerability in Visual Studio Code allows attackers to steal GitHub authentication tokens through a single click on a malicious link. The exploit leverages VS Code’s URI handler mechanism to execute unauthorized actions without user consent, potentially compromising thousands of