New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

According to a recent study, there are flaws in the way that integrated development environments (IDEs) including Microsoft Visual Studio Code, Visual Studio, IntelliJ IDEA, and Cursor manage the extension verification process, which allows hackers to run malicious code on developer computers.

In a report provided to The Hacker News, OX Security researchers Nir Zadok and Moshe Siman Tov Bustan stated, “We found that publishers can add functionality to extensions while maintaining the verified icon due to faulty verification checks in Visual Studio Code.” Because of this, malicious extensions may seem validated and authorized, which could lead to a false sense of trust.

The research specifically discovered that in order to ascertain if an extension is verified or not, Visual Studio Code makes an HTTP POST request to the domain marketplace.visualstudio[.]com.

The basic idea behind the exploitation technique is to create a malicious extension that has the same verifiable values as an extension read more about New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *