Microsoft patched a critical VS Code vulnerability on June 3, 2026, after researcher Ammar Askar revealed a one-click attack stealing GitHub OAuth tokens

Its disclosure raises questions about what security researchers should expect from vendors, and how far in advance of its publication they should notify vendors about a bug.

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking…