Skip to main content
  1. Home
  2. Computing
  3. News

Google found another critical security flaw in Microsoft Edge

Add as a preferred source on Google

Google’s Project Zero disclosed a software vulnerability in Microsoft’s Edge browser over the weekend. The flaw was first reported privately but after Microsoft failed to patch the issue in time, Google’s Project Zero team revealed the technical details of the vulnerability along with Microsoft’s response.

Let’s be clear though, this security vulnerability isn’t the kind of thing you need to run out and uninstall Edge over. Chances are you’re using a different browser anyway, but until it’s fixed maybe stick to Chrome or Firefox. The vulnerability itself establishes a workaround for one of Edge’s built-in security countermeasures, Arbitrary Code Guard (ACG). Sidestepping ACG, Google security researcher Ivan Fratric found a way to load unsigned code into memory from malicious website accessed via Microsoft Edge.

Recommended Videos

“The fix is more complex than initially anticipated, and it is very likely that we will not be able to meet the February release deadline due to these memory management issues. The team is positive that this will be ready to ship on March 13th,” Microsoft replied to Fratric’s disclosure.

However, Microsoft added, the complexity of the fix has made it difficult to nail down a fixed date for release. Microsoft is reportedly aiming for a mid-March release for the patch, but it’s unclear if the company will make that self-imposed deadline.

We’re only hearing about this now because of Google Project Zero’s security vulnerability policy. When Project Zero discovers a vulnerability, the team reaches out privately to the manufacturer of the product — in this case, Microsoft — giving the manufacturer 90 days to get a fix together before they disclose the vulnerability to the public. This particular disclosure is unlikely to make anyone in Microsoft’s Redmond, Washington, headquarters particularly happy.

As Engadget points out, it’s not the first time Google’s exploit-finding-team has rubbed Microsoft the wrong way. Google and Microsoft have all but come to blows over these disclosures in the past, with each company taking pains to poke holes in the other’s products in order to promote their own. That doesn’t appear to be the case here but it is unlikely anyone at Microsoft is going to look favorably upon this security vulnerability being thrust into the spotlight.

Jaina Grey
Former Digital Trends Contributor
Jaina Grey is a Seattle-based journalist with over a decade of experience covering technology, coffee, gaming, and AI. Her…
Windows 11 is about to turn on a setting that could hurt gaming performance
Microsoft will start enabling Memory Integrity on more Windows 11 PCs in October
A gaming PC with RGB synced lights running Apex Legends.

Microsoft is preparing to enable Memory Integrity on more Windows 11 PCs starting in October. The security feature is meant to protect systems from malicious code, but there is one reason gamers may want to keep an eye on it.

Microsoft has previously acknowledged that Memory Integrity can affect gaming performance on some Windows 11 systems. Back in 2022, the company even published instructions explaining how gamers could temporarily disable Memory Integrity and Virtual Machine Platform if they were causing problems.

Read more
AI chatbots will agree and misinform if you just put a little pressure, warns research
ChatGPT 3.5 proved the most vulnerable when false claims were repeated over and over
Claude AI on an iPhone.

AI chatbots have a well-documented habit of hallucinating information and sometimes agreeing with users even when they are wrong. A new study suggests that simply refusing to take no for an answer can make the problem worse.

Researchers from the University of Arizona tested seven AI models, including GPT-3.5, GPT-4o, GPT-4o-mini, Claude 3.5 Sonnet, Gemini 1.5 Pro, Llama 3 70B, and DeepSeek-R1. Instead of judging them from a single response, researchers kept conversations going while repeatedly feeding the models information they knew was false.

Read more
Google brings its best AI music model Lyria 3.5 to the Gemini app
Developers get full API access through Google AI Studio.
Google-gemini-lyria-3.5

Google has added Lyria 3.5, its most advanced music generation model yet, to the Gemini app. Previously available through Google's AI filmmaking tool Flow, the model is now rolling out to all Gemini users, making it easier to generate polished songs, instrumentals, and soundtracks from simple text prompts or even photos.

Lyria 3.5 makes AI-generated music sound more natural

Read more