Skip to main content

Internet Explorer users, be warned, a critical XSS bug is lurking in the shadows

microsoft browser loss internet explorer
Image used with permission by copyright holder
As if smears of past vulnerabilities and bugs weren’t enough to tarnish Internet Explorer’s reputation, a new security hole has been made public before Microsoft can plug it. This time, the discovery is quite clearly not a “gotcha” moment or the result of a rival holding a grudge.

David Leo from British security consultancy firm Deusen made the vexing disclosure, stressing there’s no universal fix available or patch downloadable. Tested on Windows 7 and 8.1 computers with IE’s version 11, the glitch allows cyber-aggressors to essentially hijack your browser.

Once a cross-site scripting (XSS) attack is remotely launched, the entire appearance of any given website can be manipulated at the hacker’s will in a matter of seconds. To illustrate the cataclysmic prospective effects of the malfunction, David Leo needs ten seconds and your approval here to plaster a “Hacked by Deusen” message on Daily Mail’s webpage.

Obviously, the publication’s actual site isn’t “hacked,” but if it’s so easy to make it look that way, think of what else a cyber-criminal could feed you. They could deceive you into handing them personal info, passwords, bank account numbers, you name it, simply by taking over trusted portals.

And the worst thing about it is you’re not even safe behind SSL encryptions. You know, addresses that start with “https.” Yup, those can be cracked too, due to the browser flaw allowing complete bypass of Same Origin Policy (SOP).

Don’t ask us to explain how the universal XSS bug came to be, we just know it’s bad. Really, really bad, and there’s no way to avoid it other than stop using Internet Explorer at once. In theory, invasions of privacy of this nature shouldn’t be possible in a pre-11 IE. But better safe than sorry, and better on Chrome or Firefox than IE.

For what it’s worth, Microsoft acknowledged the security snag without making a fuss, and confirmed work on an “update” while stating it’s not “aware of this vulnerability being actively exploited.” Whew, good thing Internet Explorer is going away.

Editors' Recommendations

Adrian Diaconescu
Former Digital Trends Contributor
Adrian is a mobile aficionado since the days of the Nokia 3310, and a PC enthusiast since Windows 98. Later, he discovered…
In a year, we’ll finally be able to say goodbye to Internet Explorer for good
microsoft issues emergency windows patch internet explorer 6 768x768

It's official -- the end of Internet Explorer is on the horizon. Microsoft confirmed what most of us already expected in a blog post released today. The company made the announcement over a year in advance. Starting on June 15, 2022, Internet Explorer will be retired and no longer supported on most versions of Windows 10. However, the legacy of IE11 lives on in Microsoft Edge.

While the vast majority of Windows 10 versions will no longer support IE11, Microsoft said that it won't be retired from all of them. This change will affect devices running Windows 10 version 20H2 and later, on both SKUs and IoT units. This means that most people are soon going to see the official retirement of Internet Explorer.

Read more
How to check ink levels on an HP, Canon, Epson, or Brother printer
A printer surrounded by several printed photos.

A printer is nothing without ink. If your cartridges start running low, you’ll probably start noticing inconsistent print quality. Your printer and whatever devices are connected to your printer should start sending you low-ink notifications, too. Not to worry though: Checking ink and laser cartridge levels is a relatively simple process, and we’ve created this guide to help you.

Read more
Best Meta Quest 2 deals: Save big on the VR headset today
A Meta Quest 2, adjusted to look green, is being used for gaming.

While the Apple Vision Pro might be at the top of the game when it comes to mixed AR experience, if you're looking for a more traditional VR experience, the Meta Quest 2 is an excellent option. Not only is it significantly cheaper than the Meta Quest 3, over $300 in some cases, but it also has a bigger library and more support. Luckily, there are quite a few excellent deals floating about, and with the Quest 2's permanent discount down to $200, it's already pretty cheap. Of course, if you'd still rather go for the fancier option, then you may want to check out these great Meta Quest 3 deals.
Today's best Meta Quest 2 deals

Meta Quest 2 (128GB) --
Meta Quest 2 (128GB) + 3 Months YouTube Premium --
Meta Quest 2 Starter Bundle (128GB) --
Meta Quest 2 Power Bundle (128GB) --

Read more