World Congress 2023 • Sep 27, 2023

You click, you lose: a practical look at VSCode's security

Thomas Chauchefoin , Paul Gerste

Think opening a workspace in VS Code is safe? Attackers can exploit its web-based architecture to execute arbitrary code the moment you click a malicious repository link.

Pause
Mute Enter Fullscreen
#1 about 5 min

Introduction to VS Code security risks and threat models

The growing threat of targeting developers and the security trade-offs of deep IDE integrations.

#2 about 6 min

VS Code architecture and security process separation boundaries

How VS Code isolates processes using Electron, webviews, and message passing to maintain security boundaries.

#3 about 3 min

Exploiting exposed network services in developer IDE extensions

How extensions that expose local web servers and debuggers introduce critical network vulnerabilities.

#4 about 5 min

Injecting malicious arguments via OS URI protocol handlers

Bypassing operating system handlers to inject malicious arguments into background execution binaries like git.

#5 about 6 min

Exploiting malicious workspace settings and local git configurations

How workspace configurations and local git hooks can execute commands before explicit trust is granted.

#6 about 4 min

Executing cross-site scripting in web views and Markdown

Weaponizing Markdown preview components and post messages to bypass same-origin policies and trigger internal commands.

#7 about 3 min

Reporting IDE vulnerabilities and bug bounty program takeaways

Analyzing bug bounty program realities for desktop applications and why IDE security boundaries remain opaque.

Matching moments

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann Chris Heilmann +3 · LIVE

4:51 min

Visual Studio Code as a target for exploitation

Raul Onitza-Klugman +1 · JS Congress

1:40 min

Identifying security risks in developer IDE environments

Niels Tanis Niels Tanis · World Congress 2022

2:48 min

Addressing remote code execution vulnerabilities in text editors

Chris Heilmann Chris Heilmann +2 · LIVE

5:26 min

Exploiting path traversal vulnerabilities in code editor extensions

Sonya Moisset · World Congress 2023

3:02 min

Mitigating extension vulnerabilities and applying workspace trust

Raul Onitza-Klugman +1 · JS Congress