Microsoft has revamped the Internet Explorer (IE Mode) feature in the Edge browser following recent reports that unknown malicious users were exploiting the feature backward compatibility to gain unauthorized access to users' devices .

The Microsoft Browser Vulnerability Research team said in a report published last week that “ malicious users were exploiting basic social engineering techniques along with unpatched (0-day) vulnerabilities in Internet Explorer’s JavaScript engine (Chakra) to gain access to victims’ devices .”
See also: Stealit malware targets Windows systems via Node.js extensions
IE Mode Abuse: How did the attack work?
Cybercriminals tricked unsuspecting users into visiting a seemingly legitimate website and then used a flyout on the page to instruct them to reload the page in IE mode. Once the page reloaded, the attackers exploited an unspecified vulnerability in the Chakra engine to achieve remote code execution. The infection sequence was completed with the attacker using a second vulnerability to escalate privileges outside of the browser and gain full control of the victim’s device.
This activity is concerning because it undermines modern defenses in Chromium and Microsoft Edge, launching it in a less secure state using Internet Explorer. This allows malicious users to escape the browser's boundaries and perform various post-exploitation steps, including malware deployment, lateral movement, and data extraction.
See also: New ChaosBot malware uses Discord channels
Microsoft did not disclose details about the nature of the vulnerabilities, the identity of the malicious user behind the attacks, or the scale of the efforts. However, it has taken steps to remove the special toolbar button, context menu, and hamburger menu items.

Users who wish to enable IE mode will now have to explicitly enable it on a case-by-case basis through the Edge browser settings:
1. Go to Settings > Default Browser
2. Locate the option labeled Allow sites to be reloaded in Internet Explorer mode and set it to Allow.
3. After enabling this setting, add the specific website or websites that require IE compatibility to the Internet Explorer mode pages list.
4. Reload the site
See also: Banking trojan Astaroth abuses GitHub

Microsoft noted that these restrictions on launching IE mode are necessary to balance security with the need to support older versions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“This approach ensures that the decision to load web content using older generation technology is significantly more deliberate,” Microsoft said. “The additional steps required to add a website to a site list are a significant obstacle for even the most determined attackers.”
