Cyber Press reports that Microsoft has rolled out new security restrictions on Internet Explorer mode in Edge after detecting that threat actors were exploiting legacy components to breach Windows systems.According to the Edge Security Team, attackers weaponized unpatched flaws in IE's Chakra JavaScript engine and used social engineering tactics to trick users into reloading malicious sites in IE mode. Once triggered, the zero-day vulnerability enabled remote code execution and privilege escalation, allowing full system compromise.The attack wave, first observed in August 2025, underscores how outdated web dependencies within enterprises, such as ActiveX controls and legacy camera interfaces, remain a security liability. In response, Microsoft has removed quick-access IE reload options and now requires users to manually enable and list approved sites for IE mode."These added steps create friction that limits automated abuse," the company said, reaffirming its push for organizations to retire legacy systems and fully adopt modern Chromium-based architectures.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




