TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Internet

Microsoft Restricts Edge IE Mode After Zero-Day Attacks

Akinola Ajibola by Akinola Ajibola
October 14, 2025
in Internet, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Microsoft claimed that it had discovered that hackers are using zero-day weaknesses in the Chakra JavaScript engine to gain access to target devices, thus it is...
  • The IT giant (Microsoft Browser Vulnerability Research team) stated that the threat actor used social engineering in conjunction with a Chakra exploit to obtain remote code...
  • Gareth Evans, Microsoft Edge Security Team Lead, states, “The [Edge security] team recently received intelligence indicating that threat actors were abusing Internet Explorer (IE) mode within...

Microsoft claimed that it had discovered that hackers are using zero-day weaknesses in the Chakra JavaScript engine to gain access to target devices, thus it is limiting access to Internet Explorer mode in the Edge browser and have redesigned the Internet Explorer (IE) mode in its Edge browser in response to “credible reports” in August 2025 that unidentified threat actors were using backward compatibility to access users’ devices without authorisation.

The IT giant (Microsoft Browser Vulnerability Research team) stated that the threat actor used social engineering in conjunction with a Chakra exploit to obtain remote code execution, although it did not provide many technical information.

Gareth Evans, Microsoft Edge Security Team Lead, states, “The [Edge security] team recently received intelligence indicating that threat actors were abusing Internet Explorer (IE) mode within Edge to gain access to unsuspecting users’ devices.”

It was also discovered that the threat actors in the assault chain described by the manufacturer of Windows deceive unwary users into visiting a website that appears to be authentic, then use a flyout on the page to direct them to reload the page in Internet Explorer mode.

Microsoft Edge features an IE mode for legacy compatibility with older technologies (ActiveX and Flash) that are still in use with a limited number of corporate apps and government portals, even though support for Internet Explorer terminated on June 15, 2022.

Threat actors were sending targets to “an official-looking spoofed website” in August, the Edge security team discovered. This persuaded users to access the page in Internet Explorer mode by use of an interface element.

After taking advantage of the Chakra zero-day, the attacker used a second vulnerability to get further access, go out of the browser, and take over the entire device.

Evans said that the Chakra bug is unpatched but did not indicate which vulnerabilities were exploited.

An unidentified weakness in the Chakra engine is allegedly weaponised by the attackers to gain remote code execution once the page has been reloaded. The adversary uses a second exploit to elevate their privileges outside of the browser at the end of the infection sequence, giving them total control over the victim’s device.

By launching it in a less secure state using Internet Explorer, the activity circumvents the modern defences built into Chromium and Microsoft Edge, which is why it is concerning. This effectively enables the threat actors to escape the browser’s confines and carry out a number of post-exploitation actions, such as malware deployment, lateral movement, and data exfiltration.

Microsoft eliminated the simple ways to activate IE mode in Edge, such as the context menu, the hamburger menu, and a dedicated toolbar button, in order to reduce the risk and to enable Internet Explorer mode, users must go to Settings > Default Browser > Permit and specify which pages should load in Internet Explorer.

Also worth reading
Microsoft’s Patch Tuesday Shows AI Is Finding Bugs Fast US Backs OpenAI In Copyright Fight Microsoft And ILO Take Digital Skills Training To Kenya’s Refugee Youth Microsoft’s AI Buildout Runs Into The Hard Math Of Chips And Power Microsoft’s China Retreat Redraws Big Tech’s AI Map Microsoft Retires Teams’ Together Mode to Simplify Video and Boost Performance

Making the activation of IE mode an intentional user action is the goal of the new limitations. Moreover, the list of domains that are permitted to load in Internet Explorer should make it extremely difficult for hackers to carry out successful breach efforts.

Enterprise policies will continue to allow commercial users to continue using IE mode, thus these changes do not affect them.

Microsoft did caution customers, nevertheless, that they should switch from Internet Explorer’s outdated web technology to more recent versions that offer better security, increased dependability, and enhanced performance.

And regarding the scope of the activities, the nature of the vulnerabilities, and the identity of the threat actor responsible for the attacks, Microsoft made no disclosures.

These limitations on starting Internet Explorer mode are required to strike a compromise between security and legacy support, according to the Windows manufacturer.

“This approach ensures that the decision to load web content using legacy technology is significantly more intentional,” Microsoft stated. “The additional steps required to add a site to a site list are a significant barrier for even the most determined attackers to overcome.”

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • edgeredesign
    Microsoft Edge Gets A Redesign Inspired By Copilot
  • edge-game-assist-1024x575
    With Edge Game Assist, Microsoft Released an in-game…
  • onedrive
    Microsoft Is Rolling Out OneDrive’s Offline Mode For Web
  • Microsoft-Edge-browser-gains-Copilot-Mode-Integrated-AI-naviagtes-searches-and-soon-shops-for-you
    Edge Gets New Copilot Mode Feature Making it an AI Browser
  • 36535b08c1738720dda7992f5f475dff
    Edge Brings Extensions to Android, Chrome Falls Behind
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • STK_109_WINDOWS_C_84940e2be8
    KB5070311 Update Causes Dark Mode Flash Issue,…
  • csm_1200x630wa_5026e9630c
    Microsoft Pushes Edge & Disables Authenticator Autofill
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Internet Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: edgeinternet explorermicrosoft
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Anthropic Says It Foiled Claude Misuse In Cyberattacks And Surveillance September 10, 2026
  • How Nigerians Can Buy Dangote Refinery Shares From Their Banking Apps September 10, 2026
  • Nvidia-Groq Deal Draws Antitrust Heat In AI Chip Race September 10, 2026
  • Boring Company Raises $3B As Musk Infrastructure Bets Grow September 10, 2026
  • AI Is Making Smartphones More Expensive September 10, 2026
  • AWS Puts $2.3B Behind Africa’s Cloud And AI Future September 10, 2026
  • MTN Nigeria Crosses 100 Million Subscribers September 10, 2026
  • AI Safety Researcher Quits As Labs Ask For Rules September 10, 2026
  • China Rejects US Claims That Its AI Firms Copied American Models September 10, 2026
  • Google’s $15B Finland AI Bet Shows Compute Is Now An Energy Race September 10, 2026
  • CBN Warns Banks And Fintechs That Cyber Risk Can Shake The System September 10, 2026
  • Apple Watch Ultra 4 Full Specs Push Battery, Satellite And AI September 9, 2026

Browse Archives

September 2026
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
282930  
« Aug    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.