This critical (CVSS 10.0) use-after-free (UAF) vulnerability in Lua scripting could allow authenticated attackers to execute ...
A malicious extension was published on Microsoft’s official VS Code marketplace, and was able to remain there for some time ...