CVE-2026-48569: Visual Studio Code Security Feature Bypass Vulnerability
Overview
- Severity
- High (CVSS 7.1)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Jun
- Released
- 2026-06-09
- Last Updated
- 2026-06-10
- EPSS Score
- 0.35% (percentile: 27.5%)
Description
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Affected Products (1)
Developer Tools
Security Updates (1)
Acknowledgments
Anonymous
Revision History
- 2026-06-09: Information published.
- 2026-06-10: Updated the Security Updates build number and title as the Chat extension is now merged into Visual Studio Code. This is an informational change only.