logo

Microsoft restricts IE mode access in Edge after zero-day attacks

ID: e28dc1a8-af00-590b-9a7a-c7b692cb28f0

STIX ID: report--e28dc1a8-af00-590b-9a7a-c7b692cb28f0

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-13

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Microsoft has restricted easy activation of Internet Explorer (IE) mode in Edge after intelligence showed threat actors abusing an unpatched Chakra JavaScript engine zero-day. Attackers lured users to a spoofed site that prompted IE mode, exploited the Chakra flaw and a secondary vulnerability to escalate privileges and escape the browser, achieving full device control; Microsoft removed toolbar/context-menu shortcuts and requires per-site IE mode approval while enterprise policies remain unaffected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.