Skip to content
MicrosoftGHSA-9rwm-gmc5-vhrf

Spoofing Vulnerability

HighCVE-2022-24526 · Published May 25, 2022 · updated May 30, 2022

A spoofing vulnerability exists in VS Code 1.65.0 and earlier versions where the `<iframe>` used for rendering webviews could be embedded in a parent frame with an unexpected origin, and the `<iframe>` would communicate with the parent frame despite its unexpected origin. ### Patches The fix is available starting with **VS Code 1.65.1**. The fix (https://github.com/microsoft/vscode/commit/c569182d081410046ee6e6938e960d1e83063612) mitigates this attack by restricting the `<iframe>` origin to a value that is computed taking the parent frame origin into account, thus isolating different parent frame origins. ### Workarounds There are no known workarounds. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/c569182d081410046ee6e6938e960d1e83063612 * An issue for this can be found at https://github.com/microsoft/vscode/issues/144703 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24526

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.65.11.65.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Information Disclosure Vulnerability
MediumOct 11, 2022
Remote Code Execution Vulnerability
HighOct 11, 2022
Elevation of Privilege Vulnerability
HighSep 14, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022
Elevation of Privilege Vulnerability
HighMay 25, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.