Two vulnerabilities are discovered in Internet Explorer and Microsoft Edge

  • Monthly updates improve devices and fix security issues.
  • Google's Project Zero identifies vulnerabilities in applications and operating systems.
  • The zero-day vulnerability affects Internet Explorer and Microsoft Edge, allowing unauthorized access.
  • It is recommended to use browsers in guest mode to reduce security risks.

Edge

Every month, major companies typically release updates to further improve device performance. They also take the opportunity to fix any security issues discovered along the way, thus keeping users protected at all times. A few years ago, Google created Project Zero, a research team dedicated to detecting security flaws in both applications and operating systems . These flaws are quickly reported to the manufacturer, giving them 90 days to fix them before the issue is officially released—a practice that puts users at risk, as cybercriminals can exploit this to obtain user information.

Leaving aside Google's policy, these two vulnerabilities are of the zero-day type, meaning they are vulnerabilities that have been there since the application was created and that the developer did not detect when creating the application or operating system, so the affected applications or systems have been and continue to be susceptible to attacks until the problem is solved.

According to Project Zero, this vulnerability is very easy to exploit, as it only requires 17 lines of HTML code focusing on the variables rcx and rax, which would allow malicious actors to control our browser and thus access the usernames and passwords we have saved in Internet Explorer or Microsoft Edge.

This time, the affected browsers are Internet Explorer and Microsoft Edge. As I mentioned at the beginning of this article, Project Zero has been forced to inform users about this vulnerability since the 90-day grace period granted to Microsoft to fix the problem has expired. According to MSPowerUser, the best way to avoid any type of attack that could take control of your browser is to run it as a guest user , that is, without any privileges.


Add as preferred source in Google