extension policy

  1. CVE-2025-12445: Edge Ingestion of Chromium Fix and SUG Guidance

    Chromium’s CVE‑2025‑12445 — described as a policy bypass in Extensions — appears in Microsoft’s Security Update Guide because Microsoft Edge (Chromium‑based) consumes Chromium open‑source code; the Security Update Guide entry is Microsoft’s downstream signal that the patched Chromium change has...
  2. The Open Source Dilemma: How Microsoft’s Extension Lock-In Undermines Developer Freedom

    Imagine waking up, opening your trusted VS Code alternative, and finding out that your favorite C/C++ extension has packed its bags and left the building – all thanks to a well-timed update from Microsoft. For many open-source developers and users of VS Code forks such as VS Codium and Cursor...