logo

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

ID: 43b7d0ba-0ae3-5fcc-8c90-8d14006ea0b2

STIX ID: report--43b7d0ba-0ae3-5fcc-8c90-8d14006ea0b2

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Pierluigi Paganini

...
...

A security researcher publicly released a proof-of-concept for a VS Code zero-day affecting github.dev that can steal GitHub OAuth tokens valid across all repos a user can access. The attack leverages a modified .vscode/extensions.json to recommend a malicious extension and uses hidden HTML inside a Jupyter Notebook to auto-approve installation, allowing stealthy token exfiltration and repository access; the researcher abandoned coordinated disclosure due to prior negative interactions with Microsoft's security response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.