Microsoft is restricting access to Internet Explorer mode in Edge browser after learning that hackers are leveraging zero-day exploits in the Chakra JavaScript engine for access to target devices. The tech giant did not share too many technical details but said that the threat actor combined social engineering with an exploit in Chakra to gain remote code execution. “The [Edge security] team recently received intelligence indicating that threat actors were abusing Internet Explorer (IE) mode within Edge to gain access to unsuspecting users’ devices,” says Gareth Evans, Microsoft Edge Security Team Lead. Although support for Internet Explorer ended on June 15, 2022, Microsoft Edge has an IE mode for legacy compatibility with older technologies (ActiveX and Flash) still in use with a small set of business applications and government portals. In August, the Edge security team learned that threat actors were directing targets to "an official-looking spoofed website" that prompted users, through an interface element, to load the page in IE mode. After exploiting the zero-day in Chakra, the attacker leveraged a second vulnerability to increase privileges and escape the browser, and take full control of the device. Evans did not provide identifiers for the exploited vulnerabilities and said the flaw in Chakra is unpatched. To mitigate the risk, Microsoft removed the methods that allowed activating IE mode in Edge through easy methods, like the dedicated toolbar button, context menu...
Microsoft restricts IE mode access in Edge after zero-day attacks
BleepingComputer
·Bill Toulas
·Published Oct 13, 2025
·Updated
Affected Software
2 affected components
Microsoft Edge
Microsoft Internet Explorer
Frequently Asked Questions
1
What security issue is the article discussing?
The article discusses the restriction of Internet Explorer mode in Microsoft Edge due to zero-day exploits targeting the Chakra JavaScript engine.
2
Who is affected by the security measures mentioned in the article?
Users of Microsoft Edge and Internet Explorer are affected by the restricted access to IE mode.
3
What type of attack is the article focused on?
The article focuses on zero-day attacks that exploit vulnerabilities in the Chakra JavaScript engine.
4
What action has Microsoft taken in response to the security threat?
Microsoft has restricted access to Internet Explorer mode in Edge to mitigate the risk of exploitation.
5
Is any specific software version mentioned in the article?
The article does not specify particular versions of Microsoft Edge or Internet Explorer affected by these restrictions.