By Pierluigi Paganini
Publication Date: 2026-06-04 09:13:00
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

A researcher publicly released a VS Code exploit within hours, citing past disputes with Microsoft over bug handling.
The security researcher Ammar Askar found a new serious zero-day in Visual Studio Code, told a contact at GitHub about it, and published a working exploit one hour later.
“Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones.” reads the report published by the researcher.
No 90-day window, no coordinated disclosure, no MSRC ticket. The researchers just dropped a PoC on the internet, because he’d been through the MSRC process before and decided once was enough.
The vulnerability resides in github.dev, the browser-based VS Code that spins up when you open a GitHub…



