GitHub Token Theft Via VS Code 1-Click Attack
A critical vulnerability in Visual Studio Code’s URI handling mechanism allows attackers to steal GitHub OAuth tokens through a single click. By exploiting the `vscode://` protocol handler and the GitHub Pull Requests extension, threat actors can craft malicious links that trigger automatic authenti