Threat Intelligence

Microsoft locks down IE mode after exploits

Closeup of mobile phone screen with logo lettering of microsoft internet explorer browser on computer keyboard

Cyber Press reports that Microsoft has rolled out new security restrictions on Internet Explorer mode in Edge after detecting that threat actors were exploiting legacy components to breach Windows systems.

According to the Edge Security Team, attackers weaponized unpatched flaws in IE's Chakra JavaScript engine and used social engineering tactics to trick users into reloading malicious sites in IE mode. Once triggered, the zero-day vulnerability enabled remote code execution and privilege escalation, allowing full system compromise.

The attack wave, first observed in August 2025, underscores how outdated web dependencies within enterprises, such as ActiveX controls and legacy camera interfaces, remain a security liability. In response, Microsoft has removed quick-access IE reload options and now requires users to manually enable and list approved sites for IE mode.

"These added steps create friction that limits automated abuse," the company said, reaffirming its push for organizations to retire legacy systems and fully adopt modern Chromium-based architectures.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds