Executive brief
Visual Studio Code is a widely used code editor relied upon by developers to write and manage applications. A flaw in its authorization checks allows a local attacker to bypass a built-in security feature without authentication, potentially compromising the integrity of code or development configurations.
Technical details
The vulnerability is an incorrect authorization issue in Visual Studio Code that enables a local attacker to bypass a security feature. The flaw is exploitable locally without requiring prior authentication or elevated privileges. This authorization bypass could allow an attacker with local system access to circumvent intended security controls, potentially leading to unauthorized access to protected resources or functionality within the editor. No active exploitation in the wild has been reported at this time.
Affected products
- Microsoft Visual Studio Code <UNKNOWN>
Timeline
- 2026-08-11: disclosed