IE, Edge Users at Risk from Serious Browser Security Flaw

A Google researcher has disclosed a serious security flaw that could make Microsoft's Internet Explorer 11 and Edge browsers unsafe to use for the time being. Microsoft has not said when it will patch the flaw, leaving millions of people around the globe at potential risk.  (The next Patch Tuesday round of security updates are scheduled for March 14.)

Credit: T.Dallas/Shutterstock

(Image credit: T.Dallas/Shutterstock)

According to Google Project Zero researcher Ivan Fratric, whose report on the flaw was made public late last week, the problem relates to how IE11 and Edge format web pages. Malicious hackers taking advantage of the flaw could build fake websites that would cause the browsers to crash, as Fratric demonstrated in his notes.

That alone isn't such a huge problem, but the flaw could also be exploited — Fratric wouldn't say how — to let those same malicious sites take control of your systems.

There's no evidence yet that anyone has exploited the flaw. But because it remains unpatched, malicious hackers may now be seeing the announcement and making webpages that could take advantage of it. We recommend not using IE11 or Edge until a patch is ready.

MORE: 12 Computer Security Mistakes You're Probably Making

Fratric tried to avoid revealing more details about the vulnerability.

"I will not make any further comments on exploitability, at least not until the bug is fixed," he wrote in his bug report. "The report has too much info on that as it is (I really didn't expect this one to miss the deadline)."

However, the U.S. government's National Vulnerability Database gives more clues, stating that: "Microsoft Internet Explorer 11 and Microsoft Edge have a type confusion issue … [that] allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element."

"Yeah, I would say that was too much information," a commenter on Ars Technica observed.

Fratric said he alerted Microsoft to the flaw in November, and disclosed it only after the end of Google Project Zero's 90-day disclosure deadline, which lets companies fix affected products within three months. (If the vendor says a flaw will be fixed within 14 days of the deadline, Google will hold off disclosure.)

The move is probably a good one. By making the information public, Google places additional pressure on Microsoft to determine what's going on and come up with a solution.

For its part, Microsoft said in a statement provided to the BBC that it has a "customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible.”

Internet Explorer 11 and Edge users are left with little to go on, and no way of mitigating the problem except hoping for the best.

To safeguard yourself, your best bet may be to stop using Edge and Internet Explorer 11 altogether and move on to something else. (Older versions of Internet Explorer may also be vulnerable.)  Mozilla Firefox, Opera and Google Chrome are not believed to suffer from the same problem.

Don Reisinger is CEO and founder of D2 Tech Agency. A communications strategist, consultant, and copywriter, Don has also written for many leading technology and business publications including CNET, Fortune Magazine, The New York Times, Forbes, Computerworld, Digital Trends, TechCrunch and Slashgear. He has also written for Tom's Guide for many years, contributing hundreds of articles on everything from phones to games to streaming and smart home.

Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Max Rockatansky (Tom Hardy) stands on the hood of a car with an explosion behind him in a promotional still for Warner Bros. "Mad Max:Fury Road"
One of the best action movies ever made is leaving Netflix very soon — here's your last day to stream 'Mad Max: Fury Road'
nvidia rtx 50 series
RTX 5060 Ti release date just tipped for April 16 — HP seemingly confirms Nvidia's next-gen GPUs