Hackers Exploit Microsoft Edge’s Internet Explorer Mode to Compromise User Devices
Microsoft Edge has addressed a critical threat involving its Internet Explorer (IE) compatibility mode. This action aims to close high-risk entry points and enhance security for both individual and enterprise users.
Microsoft Edge has addressed a critical threat involving its Internet Explorer (IE) compatibility mode. This action aims to close high-risk entry points and enhance security for both individual and enterprise users.
Despite the widespread adoption of modern web standards, many enterprise and government applications continue to rely on legacy technologies such as ActiveX controls and Flash. Microsoft Edge offers IE mode to support these older sites while maintaining a Chromium-based browsing experience. This allows organizations to designate specific domains to open in IE mode, preserving compatibility for essential business portals and seamlessly switching back to Edge’s secure environment.
However, Internet Explorer was developed before the implementation of modern defense-in-depth practices and sandbox architectures. Its JavaScript engine, Chakra, lacks many mitigations standard in contemporary browsers. When Edge invokes IE mode, it reverts to this older execution environment, potentially exposing users to vulnerabilities absent in Edge’s native engine.
The Exploit: Chakra and Entry Point Abuse
In August 2025, intelligence from the Edge security team identified malicious actors targeting IE mode to bypass Chrome-style safeguards. The attack began with a spoofed website prompting users to enable IE mode, transferring control to Chakra. This allowed attackers to deploy an undisclosed zero-day exploit, achieving remote code execution within the browser process. They then executed a second exploit to escape the browser sandbox and elevate privileges to SYSTEM level, enabling them to install malware, move laterally across networks, and exfiltrate data.
After confirming active exploitation attempts, the Edge security team removed the most accessible IE mode triggers for non-commercial users. The toolbar button, context-menu option, and menu entries for "Reload in Internet Explorer mode" were disabled. Enterprise policy controls remain unchanged, allowing administrators to enable IE mode via group policy or Microsoft Intune.
Microsoft Edge has addressed a critical threat involving its Internet Explorer (IE) compatibility mode.
For individual users requiring IE compatibility, IE mode remains available but now requires explicit configuration:
Open Edge and navigate to Settings > Default Browser. Under Allow sites to be reloaded in Internet Explorer mode, select Allow. Add necessary URLs to the Internet Explorer mode pages list. Reload the page to open it in IE mode.
These steps ensure legacy content loading is a deliberate, auditable action, raising the difficulty for attackers seeking to exploit IE vulnerabilities.
Internet Explorer 11 reached its end of life on Jun 15, 2022, and no longer receives feature updates beyond critical security patches via Edge. Microsoft advises migrating away from legacy technologies. To verify or disable IE mode, access Edge settings under Default Browser to confirm your preferred compatibility setting.
By limiting casual IE mode access and preserving enterprise policy controls, Microsoft Edge balances legacy support with modern security. These measures significantly reduce the attack surface associated with Internet Explorer’s outdated architecture while accommodating business needs. Users and administrators are encouraged to review IE mode configurations and transition to modern web standards to ensure optimal protection.
Based on reporting by GBHackers.
