Story perspectives
Microsoft Tightens Security After August 2025 IE Mode Attack
10/13/2025
30 5
1 of 1
Story summary
- The August 2025 attack used social engineering to lure users to spoofed websites and switch to Internet Explorer (IE) mode in Microsoft Edge.
- That transition exposed unpatched Chakra JavaScript engine vulnerabilities, enabling remote code execution and privilege escalation.
- Microsoft has restricted easy access to IE mode and requires manual activation for enterprise users.
- Microsoft urges enterprises to move away from legacy technologies to improve security.
