Site icon VMVirtualMachine.com

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

By Pierluigi Paganini
Publication Date: 2026-06-04 09:13:00

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

Pierluigi Paganini
June 04, 2026

A researcher publicly released a VS Code exploit within hours, citing past disputes with Microsoft over bug handling.

The security researcher Ammar Askar found a new serious zero-day in Visual Studio Code, told a contact at GitHub about it, and published a working exploit one hour later.

“Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones.” reads the report published by the researcher.

No 90-day window, no coordinated disclosure, no MSRC ticket. The researchers just dropped a PoC on the internet, because he’d been through the MSRC process before and decided once was enough.

The vulnerability resides in github.dev, the browser-based VS Code that spins up when you open a GitHub…

Exit mobile version