That logic error allowed malicious Visual Studio Code extensions to be activated and downloaded without review.
Part of the PlainSec briefing for 2026-03-28