Security Weekly Podcast Network (Audio) cover image

VSCode Vulnerabilities - Thomas Chauchefoin, Paul Gerste - PSW #804

Security Weekly Podcast Network (Audio)

00:00

Analyzing the Design and Security of VSCode

This chapter explores the design and security of Visual Studio Code (VSCode), highlighting its strong separation between functionalities and the potential ways to exploit its protection layers. The speakers discuss vulnerabilities found in VSCode, including command injections, untrusted configurations, and argument injections, emphasizing the risk to developers and researchers who work with source code from untrusted sources. They also touch on the issue of integrating VSCode with other utilities on the system and the importance of keeping the software updated for added safety.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app