A security issue in Visual Studio Code versions 1.19.0 through 1.19.2 exposed the extension host with the Node.js debugging flag enabled, causing it to listen on local TCP port 9333. That debugger interface could be reached through the Chrome DevTools Protocol, allowing an attacker to interact with the running process and inject arbitrary code into VS Code.
The reported attack path used DNS rebinding from a malicious web page to access the localhost debug endpoint, retrieve the WebSocket debugger URL, and execute commands against the exposed debugger service. The flaw was addressed in VS Code 1.19.3, and users of affected releases were urged to upgrade; the report also noted that manually starting VS Code with an inspect flag could still expose a similar local debugging risk.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2018-03-16, a public write-up described how the exposed localhost debug endpoint in VS Code could be exploited, including DNS rebinding and Chrome DevTools Protocol Runtime.evaluate to inject code into the VS Code process.
The write-up states that Node.js officially fixed the remote debugging protocol issue in its March 2018 security releases, addressing related exposure in the debugging protocol.
The issue was fixed in Visual Studio Code 1.19.3, which removed the unintended listener on port 9333 from the extension host startup behavior. Users on affected versions were advised to upgrade.
Visual Studio Code versions 1.19.0 through 1.19.2 accidentally launched the extension host with the Node.js --inspect flag, exposing a debugger interface on localhost TCP port 9333 that could allow arbitrary code execution via the Chrome DevTools Protocol.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.