Microsoft restricts IE mode access in Edge after zero-day attacks
ID: e28dc1a8-af00-590b-9a7a-c7b692cb28f0
STIX ID: report--e28dc1a8-af00-590b-9a7a-c7b692cb28f0
Feed Name: Bleeping Computer
Microsoft has restricted easy activation of Internet Explorer (IE) mode in Edge after intelligence showed threat actors abusing an unpatched Chakra JavaScript engine zero-day. Attackers lured users to a spoofed site that prompted IE mode, exploited the Chakra flaw and a secondary vulnerability to escalate privileges and escape the browser, achieving full device control; Microsoft removed toolbar/context-menu shortcuts and requires per-site IE mode approval while enterprise policies remain unaffected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
