Security researcher Ammar Askar disclosed June 2, 2026 a VS Code webview vulnerability allowing one-click theft of GitHub OAuth tokens passed to github.dev. Tokens grant full access to all repositories the victim can access. No CVE or patch as of disclosure. Mitigation: clear github.dev cookies and site data. Full PoC published on VS Code issue tracker.