Ammar Askar leaked a proof of concept exploit for a Visual Studio Code vulnerability within one hour of disclosing it to an old contact. The flaw allows attackers to push malicious extensions via the Workspace Recommendations feature by configuring repositories. The vulnerability affects repositories either created by attackers or compromised by them. This exposes users to potential code injection and unauthorized extension installation.
Tap to vote and see what everyone thinks.
ChatGPT for Google Sheets Exfiltrates Workbooks
Summary by ByteBrief