Following “credible reports” in August 2025 that unidentified threat actors were abusing the backward compatibility feature to obtain unwanted access to customers’ devices, Microsoft said that it has redesigned the Internet Explorer (IE) mode in its Edge browser.
According to a research released last week by the Microsoft Browser Vulnerability Research team, threat actors were using unpatched (0-day) weaknesses in Internet Explorer’s JavaScript engine (Chakra) in conjunction with fundamental social engineering tactics to obtain access to victim devices.
The threat actors in the assault chain described by the manufacturer of Windows have been observed to deceive unwary users into visiting a website that appears to be authentic, after which they use a flyout on the page to direct them to reload the page in Internet Explorer mode.
The attackers allegedly leveraged an unidentified Chakra engine exploit to get remote code execution when the page was reloaded. In order to get total control of the victim’s device, the adversary uses a second exploit to elevate their privileges read more about Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
