Executive brief
A vulnerability in Visual Studio Code, a popular code editor, could allow an unauthorized person to access sensitive information over a network. This occurs when a user interacts with malicious content, potentially leading to the exposure of private data or development secrets. Such an incident could compromise intellectual property or provide a foothold for further attacks on the development environment.
Technical details
An information disclosure vulnerability exists in Microsoft Visual Studio Code (CWE-200). The flaw allows an unauthenticated attacker to disclose sensitive information over a network, provided they can induce a user to perform a specific action (User Interaction: Required). According to the CVSS vector, the attack vector is network-based and has low complexity, resulting in high confidentiality impact but no impact on integrity or availability. Users are advised to apply the latest security updates from Microsoft to mitigate this risk.
Affected products
- Microsoft Visual Studio Code
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory