Tag: Microsoft Edge

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor
News

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Following "credible reports" in August 2025 that unidentified threat actors were abusing the backward compatibility feature to obtain unwanted access to customers' devices, Microsoft said that it has redesigned the Internet Explorer (IE) mode in its Edge browser. According to a research released last week by the Microsoft Browser Vulnerability Research team, threat actors were using unpatched (0-day) weaknesses in Internet Explorer's JavaScript engine (Chakra) in conjunction with fundamental social engineering tactics to obtain access to victim devices. The threat actors in the assault chain described by the manufacturer of Windows have been observed to deceive unwary users into visiting a website that appears to be authentic, after which they use a flyout on the page to direct them...
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions
News

Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions

A security vulnerability in the Microsoft Edge web browser that has since been fixed might have been leveraged to install malicious extensions and perform other nefarious tasks on users' computers. According to security researcher Oleg Zaytsev of Guardio Labs, this vulnerability may have given an attacker the ability to install more browser extensions with extensive permissions without the user's knowledge by using a private API that was first meant for marketing purposes. Following responsible disclosure in November 2023, Microsoft fixed the issue in Edge stable version 121.0.2277.83, which was released on January 25, 2024. The issue is tracked as CVE-2024-21388 (CVSS score: 6.5). The creator of Windows gave Zaytsev and Jun Kokatsu credit for bringing up the problem. Microsoft n...