Close Menu
    What's Hot

    The Key Forces Now Shaping Markets and Geopolitics by Ian Bremmer

    Opinion | Anna Paulina Luna Wants Everything Disclosed

    Many Trump Voters Are Unhappy With Handling of Iran, Economy and More Issues

    Facebook X (Twitter) Instagram
    Trending
    • The Key Forces Now Shaping Markets and Geopolitics by Ian Bremmer
    • Opinion | Anna Paulina Luna Wants Everything Disclosed
    • Many Trump Voters Are Unhappy With Handling of Iran, Economy and More Issues
    • Opinion | The Betrayal of Black Voters Threatens Our Democracy
    • Former Prince Andrew Sublet Cottages on Royal Property Where He Lived Rent-Free
    • Ye Concerts Have Been Canceled Across Europe. Why Not in the Netherlands?
    • Hopes of Lebanon Cease-fire Falter as Israel and Hezbollah Fight
    • $400M effort aims to go from mapping the brain to treating disease – GeekWire
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs

    adminBy adminFebruary 18, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananFeb 18, 2026Vulnerability / Software Security

    Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs

    Cybersecurity researchers have disclosed multiple security vulnerabilities in four popular Microsoft Visual Studio Code (VS Code) extensions that, if successfully exploited, could allow threat actors to steal local files and execute code remotely.

    The extensions, which have been collectively installed more than 125 million times, are Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview.

    “Our research demonstrates that a hacker needs only one malicious extension, or a single vulnerability within one extension, to perform lateral movement and compromise entire organizations,” OX Security researchers Moshe Siman Tov Bustan and Nir Zadok said in a report shared with The Hacker News.

    Cybersecurity

    Details of the vulnerabilities are as follows –

    • CVE-2025-65717 (CVSS score: 9.1) – A vulnerability in Live Server that allows attackers to exfiltrate local files, tricking a developer into visiting a malicious website when the extension is running, causing JavaScript embedded in the page to crawl and extract files from the local development HTTP server that runs at localhost:5500, and transmit them to a domain under their control. (Remains unpatched)
    • CVE-2025-65716 (CVSS score: 8.8) – A vulnerability in Markdown Preview Enhanced that allows attackers to execute arbitrary JavaScript code by uploading a crafted markdown (.md) file, allowing local port enumeration and exfiltration to a domain under their control. (Remains unpatched)
    • CVE-2025-65715 (CVSS score: 7.8) – A vulnerability in Code Runner that allows attackers to execute arbitrary code by convincing a user to alter the “settings.json” file through phishing or social engineering. (Remains unpatched)
    • A vulnerability in Microsoft Live Preview allows attackers to access sensitive files on a developer’s machine by tricking a victim into visiting a malicious website when the extension is running, which then enables specially crafted JavaScript requests targeting the localhost to enumerate and exfiltrate sensitive files. (No CVE, Fixed silently by Microsoft in version 0.4.16 released in September 2025)

    To secure the development environment, it’s essential to avoid applying untrusted configurations, disable or uninstall non-essential extensions, harden the local network behind a firewall to restrict inbound and outbound connections, periodically update extensions, and turn off localhost-based services when not in use.

    “Poorly written extensions, overly permissive extensions, or malicious ones can execute code, modify files, and allow attackers to take over a machine and exfiltrate information,” OX Security said. “Keeping vulnerable extensions installed on a machine is an immediate threat to an organization’s security posture: it may take only one click, or a downloaded repository, to compromise everything.”

    Code critical extensions Flaws Installs million
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe Simple Thing You Can Do to Prevent the Upsell at a Spa
    Next Article Get two years of the Complete plan for 70 percent off
    admin
    • Website

    Related Posts

    Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

    June 5, 2026

    Fake Sites, Banking Malware, and Stolen Logins

    June 5, 2026

    Why Harlem May Be the Deciding Factor in a Critical House Race

    June 5, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    The Key Forces Now Shaping Markets and Geopolitics by Ian Bremmer

    Opinion | Anna Paulina Luna Wants Everything Disclosed

    Many Trump Voters Are Unhappy With Handling of Iran, Economy and More Issues

    Opinion | The Betrayal of Black Voters Threatens Our Democracy

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by