Microsoft Edge's Internet Explorer (IE) Mode was exploited by a mysterious threat actor who leveraged a zero-day vulnerability in the legacy Chakra JavaScript engine to gain unauthorized access to user devices. The attacks, which began at least as early as August 2025, involved social engineering tactics where users were tricked into reloading seemingly legitimate websites in IE Mode. This mode, designed to provide backward compatibility for older web applications, runs web pages using the outdated Internet Explorer engine within Edge. Attackers created clones of legitimate sites and used on-page prompts to convince users to activate IE Mode, thereby exposing them to the vulnerable Chakra engine. The exploit chain consisted of a zero-day vulnerability that enabled remote code execution, followed by a privilege escalation exploit that allowed attackers to take full control of the affected system. Microsoft did not release a CVE or a specific patch for the vulnerabilities but instead responded by overhauling the IE Mode feature. The company removed all dedicated buttons, context menu options, and menu items that allowed easy access to IE Mode, making it significantly harder for users to inadvertently activate the feature. Now, users must manually enable IE Mode through the browser's settings, adding a layer of friction and reducing the attack surface. The attacks were particularly concerning because they bypassed modern security protections in Chromium-based Edge by reverting to the less secure Internet Explorer environment. Microsoft has not disclosed the identity of the threat actor, the full scope of the attacks, or the technical details of the exploited vulnerabilities. The company’s response underscores the ongoing risks associated with maintaining legacy compatibility features in modern browsers. Security experts have highlighted that such backward compatibility can inadvertently introduce significant vulnerabilities, especially when legacy code is no longer actively maintained. The incident demonstrates the importance of minimizing legacy feature exposure and the need for organizations to review their reliance on outdated web technologies. Microsoft’s swift action to restrict access to IE Mode is intended to prevent further exploitation while a more permanent solution is considered. The event has raised awareness among enterprise users and IT administrators about the dangers of enabling legacy browser modes. Organizations are advised to audit their use of IE Mode and consider alternatives to legacy web applications. The attack chain also illustrates the effectiveness of combining social engineering with technical exploits to compromise even modern browser environments. This incident serves as a cautionary tale for software vendors about the security trade-offs involved in supporting legacy features.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
By October 2025, Microsoft changed Edge's IE Mode to reduce abuse, removing easy-access buttons and requiring users to manually enable and configure the legacy feature. Multiple reports describe this as a lockdown or patching response to the zero-day attacks.
In August 2025, a threat actor began exploiting Microsoft Edge's Internet Explorer Mode to execute malicious code and take over devices. The attacks reportedly chained a zero-day in the Chakra JavaScript engine with a privilege escalation exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcenews.risky.biz
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.